Dňa 2. 9. 2014 16:47 Viktor Dukhovni  wrote / napísal(a):
and the 'file.CIDR' contains:

! 195.98.0.0/19    OK
! 195.98.128.0/19    OK
! ...    OK
! ...    OK
! 212.26.160.0/19    OK
0.0.0.0/0            REJECT

Is that so?

Yes, that should work.

No, that's invalid.  The cidr_table(5) documentation does not
include support for negation.  To specify a table of excluded
addresses:
Entry, which I mentioned above, does not work. I tested...

main.cf:
     smtpd_sasl_exceptions_networks =
            # Don't exclude these
        !cidr:${config_directory}/allow-sasl.cidr,
            # Exclude the rest
        0.0.0.0/0

allow-sasl.cidr:
     192.0.2.0/24       permit_sasl_authenticated
     10.0.0.0/8         permit_sasl_authenticated
     172.16.0.0/12      permit_sasl_authenticated
     192.168.0.0/16     permit_sasl_authenticated
     ...

The form of the RHS of allow-sasl.cidr is deliberate, instead
of disallowing authentication, one can allow all addresses to
authenticate, but use allow-sasl.cidr as an access(5) table
to allow relaying from only certain SASL clients:

     # Postfix 2.10 or later, ocnsider:  smtpd_relay_restrictions
     smtpd_recipient_restrictions =
        permit_mynetworks,
        check_client_access cidr:${config_directory}/allow-sasl.cidr,
        reject_unauth_destination,
        ... UCE restrictions ...

Yes, it works fine. Thanks.

Lubo M.

Reply via email to