>> Almost  no SMTP proxies in firewalls, I know of none, support ESMTP
>> and  SMTP  AUTH  because  the  firewall  would  need  access to the
>> user+password file.

A  content  inspector  like CBAC theoretically has no need to know the
login  credentials--it  could simply act as a TCP relay for that data,
just  as  an  HTTP  proxy  can allow basic HTTP authentication to pass
through  without  "knowing"  anything  about  its  validity on another
system.  TCP  relays  have no problem with AUTH, and they could, if so
designed, inspect traffic as they redirect it.

Still,  AFAWK,  there  aren't  any  out  there; I don't know why. Most
likely  cause  is  that  firewall vendors bit off more than they could
chew,  and  don't  want  to  write an actual modern mail server, which
would   have  to  be  tolerant  of  a  huge  number  of  RFC-permitted
permutations.

The  bottom line is that firewall vendors are not any more trustworthy
as  far  as  SMTP  security than mail server vendors. Experience shows
that a properly secured mail server, with edge routers assisting, will
always   be  "smarter"  about  its  own  vulnerabilities  than  stupid
firewalls.  Anyway,  the  number of host intrusions attempted via SMTP
vs.  the  number  of relay attempts has got to be infinitesimal, along
with the associated productivity and bandwidth losses.

-Sandy


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/

Reply via email to