SMTP ip address for VIP and relay
Hi,
Have been reading through some SMTP setups on F5 but cannot find answer to this specific question.
I have a pool of mail servers (10.0.0.1, 10.0.0.2) for VIP 9.9.9.9:25. This is used for inbound mail from the internet, as well as mail relay from internal clients. For outbound connections there is forwarding server 0.0.0.0:25 with SNAT of 9.9.9.9.
So logical traffic flow is:
- Internal client 192.168.1.1 wants to send external mail, it will send request to F5 VIP 9.9.9.9:25.
- This is load balanced to pool member 10.0.0.1:25.
- Pool member then creates new connection out to remote SMTP server 202.2.2.2:25.
- This hits F5 and matches forwarding server 0.0.0.0:25, where it's source is translated to 9.9.9.9:xxxx.
- Remote server then replies back to 9.9.9.9:xxxx, F5 checks NAT table and sends this to 10.0.0.1:yyyy.
Is this a valid setup?
The reason I chose the same 9.9.9.9 address is I'm told forward and reverse DNS needs to match to pass mail filters. Other forum posts seems to indicate people using separate addresses, or automap?
Does the F5 will keep the entries in NAT table to distinguish between the inbound connections from clients and the outbound connections initiated to external mail servers?
I want to get this basic setup working, so I can move onto data groups to distinguish for which clients to allow relay.
Thanks!
Jay