IIS SMTP Relay authentication
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > IIS and SMTP > IIS SMTP Relay authentication




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    IIS SMTP Relay authentication  
Jorge Aguiar


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
06-26-04 03:16 PM

Hi !

I've set up my IIS SMTP server to allow relaying to authenticated users.
It's working OK, but I'd like a finer control of which users are allowed to
relay.
Is there some way to prevent some (but not all) authenticated remote users
to relay, e.g. using a Windows or AD group ?

Thanks a lot !
Jorge







[ Post a follow-up to this message ]



    Re: IIS SMTP Relay authentication  
Jeff Cochran


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
06-26-04 03:16 PM

On Wed, 23 Jun 2004 15:26:26 +0100, "Jorge Aguiar" <jaguiar@labmed.pt>
wrote:

>I've set up my IIS SMTP server to allow relaying to authenticated users.
>It's working OK, but I'd like a finer control of which users are allowed to
>relay.
>Is there some way to prevent some (but not all) authenticated remote users
>to relay, e.g. using a Windows or AD group ?

Separate virtual servers is likely the method you'll need to use.
Depending on OS version of course.

Jeff





[ Post a follow-up to this message ]



    Re: IIS SMTP Relay authentication  
Jorge Aguiar


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
06-26-04 03:16 PM

I'm afraid I've lost you there. Exactly how would I use separate virtual
servers for that purpose ?
I'm using Windows Server 2003 Standard.
My SMTP server is directly connected to the Internet. I have mobile users
that use serveral ISP's on their notebooks to send and receive e-mail.
They're not computer savvy people, so it's quite difficult to have them
change their SMTP server address in Outlook each time they switch ISPs.
So I set up my server to allow relay from authenticated users.
The problem is: some of the user accounts used in the local network *must*
have blank or easy-to-guess passwords (shame !!). So, all a potential
spammer has to do is to guess a valid username.
I'd like to be able to only allow SMTP relay from users that really needed
(the mobile ones). Strong passwords are enforced for those users.

Any hints ?

Thanks a lot !
Jorge


"Jeff Cochran" <jeff.nospam@zina.com> wrote in message
news:40eec9e9.1186455022@msnews.microsoft.com...
> On Wed, 23 Jun 2004 15:26:26 +0100, "Jorge Aguiar" <jaguiar@labmed.pt>
> wrote:
> 
to[vbcol=seagreen] 
users[vbcol=seagreen] 
>
> Separate virtual servers is likely the method you'll need to use.
> Depending on OS version of course.
>
> Jeff







[ Post a follow-up to this message ]



    Re: IIS SMTP Relay authentication  
Jeff Cochran


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
06-26-04 03:16 PM

On Wed, 23 Jun 2004 20:08:11 +0100, "Jorge Aguiar" <jaguiar@labmed.pt>
wrote:

>I'm afraid I've lost you there. Exactly how would I use separate virtual
>servers for that purpose ?
>I'm using Windows Server 2003 Standard.
>My SMTP server is directly connected to the Internet. I have mobile users
>that use serveral ISP's on their notebooks to send and receive e-mail.
>They're not computer savvy people, so it's quite difficult to have them
>change their SMTP server address in Outlook each time they switch ISPs.
>So I set up my server to allow relay from authenticated users.
>The problem is: some of the user accounts used in the local network *must*
>have blank or easy-to-guess passwords (shame !!). So, all a potential
>spammer has to do is to guess a valid username.
>I'd like to be able to only allow SMTP relay from users that really needed
>(the mobile ones). Strong passwords are enforced for those users.
>
>Any hints ?

Okay.  Use separate virtual SMTP servers.  Set relay restrictions
tighter for the internal client SMTP and allow authenticated users to
relay for the external server.  Point internal clients at the internal
SMTP and external clients at the external SMTP.

While I'd work on the *must* part of the blank passwords, you could
also switch to VPN's for the mobile users and assign them an IP range
you can control.

Jeff

>Thanks a lot !
>Jorge
>
>
>"Jeff Cochran" <jeff.nospam@zina.com> wrote in message
>news:40eec9e9.1186455022@msnews.microsoft.com... 
>to 
>users 
>






[ Post a follow-up to this message ]



    Re: IIS SMTP Relay authentication  
Ralf Ziller


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
06-27-04 12:48 PM


"Jorge Aguiar" <jaguiar@labmed.pt> schrieb im Newsbeitrag
news:%2342Gy1SWEHA.3120@TK2MSFTNGP12.phx.gbl...
> Hi !
>
> I've set up my IIS SMTP server to allow relaying to authenticated users.
> It's working OK, but I'd like a finer control of which users are allowed
to
> relay.
> Is there some way to prevent some (but not all) authenticated remote users
> to relay, e.g. using a Windows or AD group ?

You could use a Protocol Event sink which drops the session if one of a list
of unsecure users authenticates.







[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 08:44 AM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register