Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Blocking Port 25 Traffic » Thanks Idiots!
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
Comcast SMTP not needed here? »
« Other port 25 checks  
AuthorAll Replies


ChrisN4BSA
Premium
join:2002-05-31
Clearwater, FL


1 edit
reply to Camelot One
Re: Thanks Idiots!

This isn't totally true. I'm net admin for a company here in Tampa, and was able to use our company SMTP server (port 25) via my home Roadrunner connection.

However - just today we have implemented a new non standard inbound SMTP port that will allow us to get around the port 25 filtering for those employees that are lucky enough (or is that unlucky?) to be on an ISP that blocks port 25 SMTP traffic.

And - as much as it sucks, amen for the ISP's blocking port 25. I hate to be punished for clueless users, but if it helps slow down the spread of viruses that spread via email, I'm all for it. I'm sick & tired of having to spend hours every day checking our mail quarantine because of all spam zombies in the wild.

cbs228
Geeks Of The World, Unite

join:2000-09-04
Saint Louis, MO

Indeed. For access to business servers or other SMTP servers that your ISP blocks, a simple ipfw rule on the server machine (or the router the server is behind) will fix this:

sudo ipfw add fwd serveraddress,25 tcp from any to me inboundport

Where serveraddress is the address of the server (usually "localhost") and inboundport is the port you want to listen on in addition to 25.

NOTE: I'm not responsible for any damage to your machine running this command may incur. Always modify ipfw rules locally as they may interrupt tcp/ip access. Tested on MacOS 10.3.2.
--
"If you stare too long into the abyss the abyss stares back at you." -Nietzsche

GENERAL FAILURE READING ©: DRIVE
(A)bort, (R)etry, (F)rivolous Lawsuits, (B)ribe Congress?


pnh102
Reptiles Are Cuddly And Pretty
Premium
join:2002-05-02
Mount Airy, MD
·Comcast

reply to ChrisN4BSA
said by ChrisN4BSA See Profile:
I hate to be punished for clueless users, but if it helps slow down the spread of viruses that spread via email, I'm all for it.
Why not yank access for the idiots who don't bother to secure their machines and/or clean up their systems?
--
Do the world a favor, Saddam. Kill yourself.


dilettante

join:2002-01-01
Haslett, MI

I've often thought that licensing (certifying) users might be a reasonable tactic. Something where you'd agree to random external audits of your network (scans and other penetration tests, monitoring traffic over an interval).

But there are cost and privacy issues I suppose, and it would really cut into the lucrative "granny (grandpaw?) AOL" market of low-use, unsophisticated users.

But I have to wonder... wouldn't it make economic sense to offer high bandwidth to "certified" users and lower bandwidth and blocked ports to those "potential problem users" who are likely to get hijacked - at the same or similar prices? If you keep your network clean and properly isolated and your boxes secure and use adequate throttling mechanisms... [takes a breath] any real hazard from running services is minimal. Violations or complaints and you'd get dropped back to the "wild west" service with ports blocked.

Sort of a "being responsible grants privileges" policy.

But maybe that's precisely where those high-cost commercial offerings come in: you pay for the privilege of being responsible. Everyone else "swims with the fishes" wearing a hardsuit.


RARPSL

join:1999-12-08
Suffern, NY

reply to ChrisN4BSA
said by ChrisN4BSA See Profile:
This isn't totally true. I'm net admin for a company here in Tampa, and was able to use our company SMTP server (port 25) via my home Roadrunner connection.

However - just today we have implemented a new non standard inbound SMTP port that will allow us to get around the port 25 filtering for those employees that are lucky enough (or is that unlucky?) to be on an ISP that blocks port 25 SMTP traffic.

And - as much as it sucks, amen for the ISP's blocking port 25. I hate to be punished for clueless users, but if it helps slow down the spread of viruses that spread via email, I'm all for it. I'm sick & tired of having to spend hours every day checking our mail quarantine because of all spam zombies in the wild.

The DESIGNATED port to use to inject Email (ie: Send it from a Mail Client) is 587 NOT 25. The problem is that many ISPs are too lazy to activate this port and require SMTP AUTH to access it. Most just say use Port25 and block out-going Port25 to other servers. IMO, ANY ISP that blocks outgoing (to non-ISP Owned SMTP Servers) that DOES NOT accept incoming Email from their customers (while those customers are using Non-ISP Connectivity) on Port 587 is a Hypocrite.
Forums » Blocking Port 25 TrafficComcast SMTP not needed here? »
« Other port 25 checks  


Thursday, 26-Nov 19:10:34 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [109] New AT&T Ad Campaign Hits Back At Verizon
· [107] Time Warner Cable Fires Broadside At Broadcasters
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [69] TiVo Sees Record Customer Losses
· [61] In-Flight Internet Headed For Bumpy Landing?
· [44] Thanksgiving Open Thread
· [37] ICANN Slams DNS Redirection
· [34] Senators Want ACTA Made Public
· [34] Despite Billions In USF Fees, U.S. Libraries Lack Bandwidth
Most people now reading
· I'll Just Unplug That... [No, I Will Not Fix Your #@$!! Computer]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· So we need a legitimate reason to use a lot of bandwidth? [TekSavvy]
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· SSD [Computer Hardware Discussion/Reviews]
· Windows 7 boot manager editing questions [Microsoft Help]
· Whats the big deal about being "Old School"....? [World of Warcraft]