>> Almost no SMTP proxies in firewalls, I know of none, support ESMTP >> and SMTP AUTH because the firewall would need access to the >> user+password file.
A content inspector like CBAC theoretically has no need to know the login credentials--it could simply act as a TCP relay for that data, just as an HTTP proxy can allow basic HTTP authentication to pass through without "knowing" anything about its validity on another system. TCP relays have no problem with AUTH, and they could, if so designed, inspect traffic as they redirect it. Still, AFAWK, there aren't any out there; I don't know why. Most likely cause is that firewall vendors bit off more than they could chew, and don't want to write an actual modern mail server, which would have to be tolerant of a huge number of RFC-permitted permutations. The bottom line is that firewall vendors are not any more trustworthy as far as SMTP security than mail server vendors. Experience shows that a properly secured mail server, with edge routers assisting, will always be "smarter" about its own vulnerabilities than stupid firewalls. Anyway, the number of host intrusions attempted via SMTP vs. the number of relay attempts has got to be infinitesimal, along with the associated productivity and bandwidth losses. -Sandy Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/
