Author Topic: No POP3 after enabling Firewall  (Read 6136 times)

cpu_f1xer

  • Zen Apprentice
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
No POP3 after enabling Firewall
« on: May 18, 2008, 04:28:26 am »
I installed ebox on a server fresh from the insallation disc downloaded from eboxplatform.
Mail worked great until I enabled the Firewall. Now SMTP works fine but POP3 seems to be prohibited on the external network interface.
Here is what I've done so far...
  • I created a Service Name called pop configured to allow TCP/UDP source port 110 to destination port 110.
  • Added a packet filter rule allowing acceptance of any external network source traffic to the service name pop.
  • Added this rule to the top of the priority list.
Still no luck.
Goofy thing is there is no service or rule for SMTP (port 25) but it works fine. Makes me wonder about the word "Firewall" on this platform.
I verified that POP3 is enabled on the Mail Services tab of the Mail management page.
External interface is directly on public network with no router (other than ISP cable modem) in between.
Any suggestions?
« Last Edit: May 18, 2008, 04:44:10 am by cpu_f1xer »

sixstone

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1417
  • Karma: +26/-0
    • View Profile
    • Sixstone's blog
Re: No POP3 after enabling Firewall
« Reply #1 on: May 18, 2008, 03:37:16 pm »
The POP3 clients does not connect from 110 port. So you may change in pop service configuration in source port from 110 to any. Now it should work fine.

If you're using POPS, change the destination port from 110 to 995.

Hope this may be helpful.
My secret is my silence...

cpu_f1xer

  • Zen Apprentice
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Re: No POP3 after enabling Firewall
« Reply #2 on: May 18, 2008, 11:40:00 pm »
That worked. I never knew the client doesn't initiate on 110.
Question now is why does SMTP (port 25) work without a service rule?
« Last Edit: May 19, 2008, 06:25:19 am by cpu_f1xer »

sixstone

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1417
  • Karma: +26/-0
    • View Profile
    • Sixstone's blog
Re: No POP3 after enabling Firewall
« Reply #3 on: May 19, 2008, 08:50:47 am »
That worked. I never knew the client doesn't initiate on 110.
Question now is why does SMTP (port 25) work without a service rule?

A mystery  ;D... anyway in future versions this behaviour may change so you'd better add a rule to the SMTP traffic as well... :)
My secret is my silence...

HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Re: No POP3 after enabling Firewall
« Reply #4 on: May 29, 2008, 06:47:01 pm »
Sorry for using your thread but you seem to get it right Pop/smtp mail in all

i`ve got ebox setup and all mail via ethernet works but the mail to external sources does not!!!
Can you help me with this issue here`s what i get on outlook if i try to send mail to outside my ethernet
"The message could not be sent because one of the recipients was rejected by the server. The rejected e-mail address was 'hanneswallace@yahoo.com'. Subject 'test', Account: '192.127.80.250', Server: '192.127.80.250', Protocol: SMTP, Server Response: '554 <hanneswallace@yahoo.com>: Relay access denied', Port: 25, Secure(SSL): No, Server Error: 554, Error Number: 0x800CCC79" any help would be deerly apriciated  :)
Only people that wants to no more will ask!!

sixstone

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1417
  • Karma: +26/-0
    • View Profile
    • Sixstone's blog
Re: No POP3 after enabling Firewall
« Reply #5 on: June 02, 2008, 10:29:07 am »
You may change your mail configuration by adding allowed relay objects, the wanted hosts to send mail from. This setting is set in Mail -> General -> Settings.

Deny is default because of spam possible issues. Therefore, you may create an object with your our LAN network address as member and then allow this object to send mail from your mail system.

Hope this helps.
My secret is my silence...

HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Re: No POP3 after enabling Firewall
« Reply #6 on: June 02, 2008, 06:10:12 pm »
I did do that allready no success but thanx for your reply  ;)
Only people that wants to no more will ask!!

cpu_f1xer

  • Zen Apprentice
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Re: No POP3 after enabling Firewall
« Reply #7 on: June 02, 2008, 06:56:19 pm »
Strange. I am now experiencing a similar issue. I have mail setup to require authentication. I configured outlook to login with same credentials as POP but I get an error "None of the authentication methods supported by this client are supported by your server."
I have tried a variety of settings in outlook with no luck. If I use no authentication to send mail then the server rejects because it does not allow relaying (which is what I want).
Any clues would be appreciated.
« Last Edit: June 02, 2008, 07:06:39 pm by cpu_f1xer »

cpu_f1xer

  • Zen Apprentice
  • *
  • Posts: 5
  • Karma: +0/-0
    • View Profile
Re: No POP3 after enabling Firewall
« Reply #8 on: June 02, 2008, 10:35:56 pm »
Solved my own problem.
Needed to select TLS encryption type in the Advanced tab of Outlook's E-mail settings dialog box.
Uses invalid certificate but who cares?

 ;)

javi

  • Zen Hero
  • *****
  • Posts: 1042
  • Karma: +0/-0
    • View Profile
Re: No POP3 after enabling Firewall
« Reply #9 on: June 02, 2008, 10:42:10 pm »
Just for your information this is what you have to do to be able to use the SMTP server and send emails with some Outlook versions:

- If the firewall is enabled in eBox you will have to allow the destination tcp port 465, save changes
- In outlook you will have to configure it to use port 465 instead of 25, use secure mode and stuff

Outlook needs to use that port instead of 25 to work properly.

From the next eBox version onwards you won't have to manually add port 465 port, we will include in our "Mail system" service by default.

As cpu_f1xer points, newer Outlook versions need to be configured on the advanced tab to support TLS encryption.


HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Re: No POP3 after enabling Firewall
« Reply #10 on: June 02, 2008, 11:47:05 pm »
Trail & error is no option for you guys thanx hey you helped a lot thanx alot  :D
Only people that wants to no more will ask!!

HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Re: No POP3 after enabling Firewall
« Reply #11 on: June 03, 2008, 12:02:06 am »
In my queue management this accurs now im no guru but I think this may be my problem and this is all Greek to afrikaans speaking guy I DO NOT KNOW WHAT THIS IS call me stupid but this is the way i learn and im not giving up

/etc/cron.daily/logrotate:
error: ebox-soap:1 lines must begin with a keyword or a filename (possibly in double quotes)
error: ebox-soap:16 unxpected }
run-parts: /etc/cron.daily/logrotate exited with return code 1
 
any help would be greatly appreciated Thanx
Only people that wants to no more will ask!!

HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Re: No POP3 after enabling Firewall
« Reply #12 on: June 03, 2008, 12:38:28 am »
one step closer now it doesnt give me relay denied but it does give me an error and its now time out wile connecting
If i run the test settings it states that outlook can connect and that i need to check the port and if the server requires ssl support


 ???any help?
 



Only people that wants to no more will ask!!

sixstone

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1417
  • Karma: +26/-0
    • View Profile
    • Sixstone's blog
Re: No POP3 after enabling Firewall
« Reply #13 on: June 03, 2008, 09:00:09 am »
In my queue management this accurs now im no guru but I think this may be my problem and this is all Greek to afrikaans speaking guy I DO NOT KNOW WHAT THIS IS call me stupid but this is the way i learn and im not giving up

/etc/cron.daily/logrotate:
error: ebox-soap:1 lines must begin with a keyword or a filename (possibly in double quotes)
error: ebox-soap:16 unxpected }
run-parts: /etc/cron.daily/logrotate exited with return code 1
 
any help would be greatly appreciated Thanx
You may uninstall ebox-soap since you're not using it :) (I'm sure about this) by running:
Code: [Select]
$ apt-get remove ebox-soap

And remove manually /etc/logrotate.d/ebox-soap file. Anyway, it's a known fixed bug.

Thanks for your report.
My secret is my silence...

HANNES1985

  • Zen Warrior
  • ***
  • Posts: 141
  • Karma: +0/-0
    • View Profile
    • CSIWISP
Re: No POP3 after enabling Firewall
« Reply #14 on: June 03, 2008, 06:47:46 pm »
I have uninstalled soap but still shows me this error (connect to 127.0.0.1[127.0.0.1]: Connection refused) with
the same on my previous post. How do you remove this (/etc/logrotate.d/ebox-soap) manually, i did run the uninstall code (apt-get remove ebox-soap) within my server, and it did remove it coz i cant see it in my GUI anymore

Thank you for your help on this matter.. :)
Only people that wants to no more will ask!!