Re: [pfSense Support] spamd package

2008-05-01 Thread Michel Servaes




What I just come to think of... should I disable the rule of pfsense
itself ?
I have used pfSense for almost 2 months now, and have opened port 25 in
the very beginning... might it be that this open port is still there,
and that spamd also has an open port ?


I think I have the sitation below, when installing spamd ?

WAN --> port25 --> LAN 192.168.10.200
WAN --> port25 --> LOCALHOST --> LAN 192.168.10.200

However, when telnetting into port 25 (with or without spamd) I get the
answer of my mailserver (very slow with spamd installed, but I guess
that would be that option to disappoint a spammer :) )


Michel Servaes schreef:

  
It still won't react... I waited more than 30 minutes, but it still
doesn't come through...
I see in the System log a lot of spamd(1080), disconnect after xxx
seconds...
  
This is the snip in my rules.debug :
  
spam table 
table  persist
table  persist
table  persist
table  persist file "/var/db/whitelist.txt"
rdr pass on fxp0 proto tcp from  to port smtp ->
127.0.0.1 port spamd
rdr pass on fxp0 proto tcp from  to port smtp ->
127.0.0.1 port spamd
rdr pass on fxp0 proto tcp from ! to port smtp ->
127.0.0.1 port spamd
rdr pass on fxp0 proto tcp from  to port smtp ->
192.168.10.200 port smtp
  
  
192.168.10.200 is our local mailserver.
  
  
  
Scott Ullrich schreef:
  
On 5/1/08, Michel Servaes <[EMAIL PROTECTED]> wrote:
  

  So you don't config anything in the SpamD settings at all ?
 The nextMTA shouldn't be your mailserver ?? I tried with and without, but
still no mail gets delivered...



Yep.

  

   If I send a mail (from a spamless address), should the mail be visible in
the SpamD database ??
 And how much time will it take to be delivered in the true mailbox? 25
minutes, or is this a complete other thing here (the greylist I mean)



About 30 minutes to white list.

  

   I used to use MDaemon's SPAM (which was quite easy, since it almost works
without a hassle), so this is quite a new approach for me...



Verify in /tmp/rules.debug that you have a rdr for port 25 going to
the next mta.  In fact, post the block of rules around the SpamD rdr.

Scott

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

  
  




-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] spamd package

2008-05-01 Thread Michel Servaes




It still won't react... I waited more than 30 minutes, but it still
doesn't come through...
I see in the System log a lot of spamd(1080), disconnect after xxx
seconds...

This is the snip in my rules.debug :

spam table 
table  persist
table  persist
table  persist
table  persist file "/var/db/whitelist.txt"
rdr pass on fxp0 proto tcp from  to port smtp ->
127.0.0.1 port spamd
rdr pass on fxp0 proto tcp from  to port smtp ->
127.0.0.1 port spamd
rdr pass on fxp0 proto tcp from ! to port smtp ->
127.0.0.1 port spamd
rdr pass on fxp0 proto tcp from  to port smtp ->
192.168.10.200 port smtp


192.168.10.200 is our local mailserver.



Scott Ullrich schreef:

  On 5/1/08, Michel Servaes <[EMAIL PROTECTED]> wrote:
  
  
So you don't config anything in the SpamD settings at all ?
 The nextMTA shouldn't be your mailserver ?? I tried with and without, but
still no mail gets delivered...

  
  
Yep.

  
  
 If I send a mail (from a spamless address), should the mail be visible in
the SpamD database ??
 And how much time will it take to be delivered in the true mailbox? 25
minutes, or is this a complete other thing here (the greylist I mean)

  
  
About 30 minutes to white list.

  
  
 I used to use MDaemon's SPAM (which was quite easy, since it almost works
without a hassle), so this is quite a new approach for me...

  
  
Verify in /tmp/rules.debug that you have a rdr for port 25 going to
the next mta.  In fact, post the block of rules around the SpamD rdr.

Scott

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

  




-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] spamd package

2008-05-01 Thread Scott Ullrich
On 5/1/08, Michel Servaes <[EMAIL PROTECTED]> wrote:
> So you don't config anything in the SpamD settings at all ?
>  The nextMTA shouldn't be your mailserver ?? I tried with and without, but
> still no mail gets delivered...

Yep.

>  If I send a mail (from a spamless address), should the mail be visible in
> the SpamD database ??
>  And how much time will it take to be delivered in the true mailbox? 25
> minutes, or is this a complete other thing here (the greylist I mean)

About 30 minutes to white list.

>  I used to use MDaemon's SPAM (which was quite easy, since it almost works
> without a hassle), so this is quite a new approach for me...

Verify in /tmp/rules.debug that you have a rdr for port 25 going to
the next mta.  In fact, post the block of rules around the SpamD rdr.

Scott

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] spamd package

2008-05-01 Thread Michel Servaes

So you don't config anything in the SpamD settings at all ?
The nextMTA shouldn't be your mailserver ?? I tried with and without, 
but still no mail gets delivered...


If I send a mail (from a spamless address), should the mail be visible 
in the SpamD database ??
And how much time will it take to be delivered in the true mailbox? 25 
minutes, or is this a complete other thing here (the greylist I mean)


I used to use MDaemon's SPAM (which was quite easy, since it almost 
works without a hassle), so this is quite a new approach for me...




Vaughn L. Reid III schreef:
I have been successfully using the spamd package for about 2 weeks at 
one of my client sites, and it is working wonderfully.  It has reduced 
the amount of spam that the site's email server was receiving from 
about 15000 per day to about 50 to 75 per day.

I configured the package as follows:

On the external spam data sources page, I have the following 2 items 
configured:

provider:  spamhaus
type:  blacklist
provider method:  url
url:  zen.spamhaus.org

provider:  uceprotect network
type:  blacklist
provider method:  file
file:  
http://wget-mirrors.uceprotect.net/rbldnsd-all/dnsbl-1.uceprotect.net.gz


On the white list tab, I have the client's local email server's IP 
address listed.


I left the default configuration on the spamd settings tab.

I am having excellent luck with this package running on a pair of 
firewalls using CARP.  I manually replicated my settings on both 
boxes, and it successfully works during failover (although the 
settings and spam database don't replicate -- but that's a given with 
most of the add-on packages).


I believe that you may be experiencing problems because you don't have 
your local email server white listed.


Vaughn Reid III


Michel Servaes wrote:

Hi,


I just tried to install spamd today, but it seems to block all my 
messages.

I've waited 25 minutes, and still no mail arrives.

I also tried to add some blacklist servers from the openbsd/spamd 
page, but it seems not to really work.


It just kept three entries in the greylist, and nothing else passed 
into that list, nor anything went through the mailserver I entered as 
next MTA.


When I telnetted into the SMTP port on my WAN side (from another 
location obviously), the SMTP HELO string came very slowly (but 
changing the value to '0' for the delay didn't make it faster).



Where can I find good info on how to configure it basic... from that 
point I could maybe tweak a little, but a basic guideline would be 
great to start with.



Kind regards,
Michel

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] spamd package

2008-05-01 Thread Vaughn L. Reid III

Gary,

Thanks for the suggestion.  My client is a not-for-profit library.  They 
own the hardware.  I provide consulting services/labor.  So, I believe 
that their usage is appropriate.  I do not sale pre-configured appliances.






Gary Buckmaster wrote:

Vaughn,

You should re-visit the spamhaus terms of service for their Zen 
service.  It is not free for commercial use as you are apparently doing.

Otherwise, thank you for the feedback on the package.
-Gary

Vaughn L. Reid III wrote:
I have been successfully using the spamd package for about 2 weeks at 
one of my client sites, and it is working wonderfully.  It has 
reduced the amount of spam that the site's email server was receiving 
from about 15000 per day to about 50 to 75 per day.

I configured the package as follows:

On the external spam data sources page, I have the following 2 items 
configured:

provider:  spamhaus
type:  blacklist
provider method:  url
url:  zen.spamhaus.org

provider:  uceprotect network
type:  blacklist
provider method:  file
file:  
http://wget-mirrors.uceprotect.net/rbldnsd-all/dnsbl-1.uceprotect.net.gz


On the white list tab, I have the client's local email server's IP 
address listed.


I left the default configuration on the spamd settings tab.

I am having excellent luck with this package running on a pair of 
firewalls using CARP.  I manually replicated my settings on both 
boxes, and it successfully works during failover (although the 
settings and spam database don't replicate -- but that's a given with 
most of the add-on packages).


I believe that you may be experiencing problems because you don't 
have your local email server white listed.


Vaughn Reid III


Michel Servaes wrote:

Hi,


I just tried to install spamd today, but it seems to block all my 
messages.

I've waited 25 minutes, and still no mail arrives.

I also tried to add some blacklist servers from the openbsd/spamd 
page, but it seems not to really work.


It just kept three entries in the greylist, and nothing else passed 
into that list, nor anything went through the mailserver I entered 
as next MTA.


When I telnetted into the SMTP port on my WAN side (from another 
location obviously), the SMTP HELO string came very slowly (but 
changing the value to '0' for the delay didn't make it faster).



Where can I find good info on how to configure it basic... from that 
point I could maybe tweak a little, but a basic guideline would be 
great to start with.



Kind regards,
Michel

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]




-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] spamd package

2008-05-01 Thread Gary Buckmaster

Vaughn,

You should re-visit the spamhaus terms of service for their Zen 
service.  It is not free for commercial use as you are apparently doing. 

Otherwise, thank you for the feedback on the package. 


-Gary

Vaughn L. Reid III wrote:
I have been successfully using the spamd package for about 2 weeks at 
one of my client sites, and it is working wonderfully.  It has reduced 
the amount of spam that the site's email server was receiving from 
about 15000 per day to about 50 to 75 per day.

I configured the package as follows:

On the external spam data sources page, I have the following 2 items 
configured:

provider:  spamhaus
type:  blacklist
provider method:  url
url:  zen.spamhaus.org

provider:  uceprotect network
type:  blacklist
provider method:  file
file:  
http://wget-mirrors.uceprotect.net/rbldnsd-all/dnsbl-1.uceprotect.net.gz


On the white list tab, I have the client's local email server's IP 
address listed.


I left the default configuration on the spamd settings tab.

I am having excellent luck with this package running on a pair of 
firewalls using CARP.  I manually replicated my settings on both 
boxes, and it successfully works during failover (although the 
settings and spam database don't replicate -- but that's a given with 
most of the add-on packages).


I believe that you may be experiencing problems because you don't have 
your local email server white listed.


Vaughn Reid III


Michel Servaes wrote:

Hi,


I just tried to install spamd today, but it seems to block all my 
messages.

I've waited 25 minutes, and still no mail arrives.

I also tried to add some blacklist servers from the openbsd/spamd 
page, but it seems not to really work.


It just kept three entries in the greylist, and nothing else passed 
into that list, nor anything went through the mailserver I entered as 
next MTA.


When I telnetted into the SMTP port on my WAN side (from another 
location obviously), the SMTP HELO string came very slowly (but 
changing the value to '0' for the delay didn't make it faster).



Where can I find good info on how to configure it basic... from that 
point I could maybe tweak a little, but a basic guideline would be 
great to start with.



Kind regards,
Michel

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]




-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] spamd package

2008-05-01 Thread Vaughn L. Reid III
I have been successfully using the spamd package for about 2 weeks at 
one of my client sites, and it is working wonderfully.  It has reduced 
the amount of spam that the site's email server was receiving from about 
15000 per day to about 50 to 75 per day. 


I configured the package as follows:

On the external spam data sources page, I have the following 2 items 
configured:

provider:  spamhaus
type:  blacklist
provider method:  url
url:  zen.spamhaus.org

provider:  uceprotect network
type:  blacklist
provider method:  file
file:  
http://wget-mirrors.uceprotect.net/rbldnsd-all/dnsbl-1.uceprotect.net.gz


On the white list tab, I have the client's local email server's IP 
address listed.


I left the default configuration on the spamd settings tab.

I am having excellent luck with this package running on a pair of 
firewalls using CARP.  I manually replicated my settings on both boxes, 
and it successfully works during failover (although the settings and 
spam database don't replicate -- but that's a given with most of the 
add-on packages).


I believe that you may be experiencing problems because you don't have 
your local email server white listed.


Vaughn Reid III


Michel Servaes wrote:

Hi,


I just tried to install spamd today, but it seems to block all my 
messages.

I've waited 25 minutes, and still no mail arrives.

I also tried to add some blacklist servers from the openbsd/spamd 
page, but it seems not to really work.


It just kept three entries in the greylist, and nothing else passed 
into that list, nor anything went through the mailserver I entered as 
next MTA.


When I telnetted into the SMTP port on my WAN side (from another 
location obviously), the SMTP HELO string came very slowly (but 
changing the value to '0' for the delay didn't make it faster).



Where can I find good info on how to configure it basic... from that 
point I could maybe tweak a little, but a basic guideline would be 
great to start with.



Kind regards,
Michel

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] spamd package

2007-02-02 Thread Josep Pujadas i Jubany
On Thu, 1 Feb 2007 23:26:38 +0100, Josep Pujadas i Jubany wrote
> -

Is somebody working with the spamd package ???

With pfsense 1.0.1 it seems that the external providers and whitelist are 
not working. GUI don't have also a place to put blacklists (?).

I had to make the following script:

#!/bin/sh 
# 
# Josep Pujadas i Jubany (02-feb-2007) 
# Updating /var/db/blacklist.txt and /var/db/whitelist.txt for pfSense 1.0.1 
# 
mkdir tmp 
cd tmp 
# 
/usr/bin/fetch http://www.openbsd.org/spamd/spews_list_level1.txt.gz 
/usr/bin/gunzip spews_list_level1.txt.gz 
cat spews_list_level1.txt > blacklist.txt 
cat ../lf.txt >> blacklist.txt 
# 
/usr/bin/fetch http://www.openbsd.org/spamd/chinacidr.txt.gz 
/usr/bin/gunzip chinacidr.txt.gz 
cat chinacidr.txt >> blacklist.txt 
cat ../lf.txt >> blacklist.txt 
# 
/usr/bin/fetch http://www.openbsd.org/spamd/koreacidr.txt.gz 
/usr/bin/gunzip koreacidr.txt.gz 
cat chinacidr.txt >> blacklist.txt 
cat ../lf.txt >> blacklist.txt 
# 
/usr/bin/fetch http://www.bellera.cat/josep/pfsense/spamd/whitelist.txt 
# 
mv blacklist.txt /var/db/. 
mv whitelist.txt /var/db/. 
/usr/local/sbin/spamd-setup 
# 
cd .. 
rm -R tmp 

(lf.txt is just a file with a blank line ...)

Now the GUI says:

Database totals: 
  70 total items in the whitelist. 
  15357 total items in the blacklist. 
  120 total items in the SpamDB. 

But I'm not sure that my spmad is good working. I think it does'nt not use  
blacklist.txt and whitelist.txt. For example, messages from gmail.com (a pool 
of mailservers) continue to be greylisted ...

Please help!

Josep Pujadas


-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]