I have other things I would like to do aside from just the email if I can
control the presenting IP on mikrotiks, but this is todays need.

All the routers loopback/router IDs are /32s from a global /24 and if we
have 250 some infrastructure routers at some point in time, We would have a
"guy for that"

even with authentication I prefer to firewall off mailservers completely, I
dont know enough to always ensure every patch is applied for exposed mail
servers for every new vulnerability, thats why I start with deny all on an
external firewall and then only allow specific devices to even touch them.
My incompetence in securing mailservers is only matched by my willingness
to do things in a tedious fashion to circumvent my incompetence.

On Tue, Aug 9, 2016 at 12:05 PM, George Skorup <[email protected]> wrote:

> I have an internal anycast address that's shared by three machines that
> provides SMTP, DNS and syslog to infrastructure devices. SMTP auth. Works.
> No dicking. The MT will do a route lookup and use the exit interface's
> source address. Doesn't matter because of SMTP auth. It's easier than
> setting up a bunch of rules because shit changes all the time.
>
> On 8/9/2016 11:51 AM, That One Guy /sarcasm wrote:
>
> right or wrong, i want to set up an open mail relay on our network for
> mikrotik backups. I want to lock the relay down to only accept traffic from
> our internal subnet for loopback IPs on the site routers. How do I make
> specific traffic always present as the same IP no matter which interface it
> exits since i cant seem to find a way to masquerade the output chain
>
> if it is doable, is there also a way to add a line to our default configs
> that will set the presentation IP to whatever the loopback IP on that
> device is?
>
> --
> If you only see yourself as part of the team but you don't see your team
> as part of yourself you have already failed as part of the team.
>
>
>


-- 
If you only see yourself as part of the team but you don't see your team as
part of yourself you have already failed as part of the team.

Reply via email to