Community discussions

MikroTik App
 
Ernstm
just joined
Topic Author
Posts: 17
Joined: Mon Jun 23, 2008 10:03 am

Mail server nat

Mon Jun 23, 2008 10:22 am

I have a mail server on an internal address behind my Firewall.

The problem i have is that if I DNAT all port 25 and port 110 traffic to the server, i am unable to communicate with the server if I don't masquerade my network behind the Firewalls internal Ether port. This would normally be fine, but the problem is that any IP based RBL checks my mail server tries to do fails, as the masquerade removes the source address. (RBL's require the source address of the original message)

Am i doing something wrong?
 
User avatar
ashish
Long time Member
Long time Member
Posts: 546
Joined: Mon Feb 12, 2007 5:50 am
Location: Virginia, USA.

Re: Mail server nat

Mon Jun 23, 2008 10:36 am

Hi,

You have to configure "NETMAP".

add Two rules under firewall NAT, and action=netmap
 
Ernstm
just joined
Topic Author
Posts: 17
Joined: Mon Jun 23, 2008 10:03 am

Re: Mail server nat

Mon Jun 23, 2008 10:53 am

I have set the Netmap rules. Should I exclude the mail server IP from the internal masquerade rule? As the masquerade rule is to masquerade all requests to the internal network behind the internal interface of the Router. And as such i still loose the original IP.
 
User avatar
ashish
Long time Member
Long time Member
Posts: 546
Joined: Mon Feb 12, 2007 5:50 am
Location: Virginia, USA.

Re: Mail server nat

Mon Jun 23, 2008 11:05 am

The netmap rule should be kept before masqurade rule.

There will be two NAT rule.
1. src-nat
2. dst-nat

and for both action=netmap
 
Ernstm
just joined
Topic Author
Posts: 17
Joined: Mon Jun 23, 2008 10:03 am

Re: Mail server nat

Mon Jun 23, 2008 11:10 am

Thanks for the reply.

Am i correct in assuming that the src-nat rule should be set to netmap to the public IP?
 
User avatar
ashish
Long time Member
Long time Member
Posts: 546
Joined: Mon Feb 12, 2007 5:50 am
Location: Virginia, USA.

Re: Mail server nat

Mon Jun 23, 2008 11:23 am

NAT rule=src-nat, src-address=private IP, netmap-to-address=publicIP
NAT rule=dst-nat, dst-address=Public IP, netmap-to-address=Private IP
 
Ernstm
just joined
Topic Author
Posts: 17
Joined: Mon Jun 23, 2008 10:03 am

Re: Mail server nat

Mon Jun 23, 2008 11:28 am

Ok. I have done so.

Should i then not be able to use the server without the masquerade rule? I am asking because if i exclude the server's internal IP from the masquerade rule I am unable to send/receive mail.
 
Ernstm
just joined
Topic Author
Posts: 17
Joined: Mon Jun 23, 2008 10:03 am

Re: Mail server nat

Mon Jun 23, 2008 12:11 pm

OK. I have the netmap rules set up as above. And the packet counters are running, but I still have the problem where the masquerade rule below the netmap rules cause me to lose the original IP address. If I exclude the mail server's internal IP from the masquerade rule, I am unable to send/receive from any of the internal PC's.

Any ideas?
 
Ernstm
just joined
Topic Author
Posts: 17
Joined: Mon Jun 23, 2008 10:03 am

Re: Mail server nat

Mon Jun 23, 2008 2:44 pm

For the record I have, with the help of a local Mikrotik guru, managed to get the server to work without the masquerade rule. However, I cannot seem to get the RBL checking to work as the server still reports that it is receiving all mail from a local address and as such cannot check the source IP address.

Anybody else having this problem?
 
changeip
Forum Guru
Forum Guru
Posts: 3830
Joined: Fri May 28, 2004 5:22 pm

Re: Mail server nat

Mon Jun 23, 2008 8:23 pm

post the following:

/ip firewall nat export

Sam
 
User avatar
gmsmstr
Trainer
Trainer
Posts: 982
Joined: Fri Jun 04, 2004 2:22 am
Location: St. Louis, MO
Contact:

Re: Mail server nat

Mon Jun 23, 2008 8:34 pm

Just need a dual nat setup. More confusing than it actually is. I'm sure a consultant can help you out..

Who is online

Users browsing this forum: Bing [Bot], GoogleOther [Bot] and 116 guests