[H-GEN] Proxy servers

Robert Brockway robert at timetraveller.org
Tue Jun 25 00:21:57 EDT 2002


[ Humbug *General* list - semi-serious discussions about Humbug and     ]
[ Unix-related topics. Posts from non-subscribed addresses will vanish. ]

On Tue, 25 Jun 2002, Nikolai Lusan wrote:

> It is quie easy, there are a number of HOWTO's that cover the various
> stuff you need. Look at the netfilter HOWTO for iptables and masq, squid
> is easy to setup (kewl snmp feature for stat gathering and very useful
> acl structure with redirecter support for content control). You will
> need an MTA of choice for outgoing mail (or you could just dnat to the

Generally [1] a bad idea to NAT the MTA as it doesn't take into account
bounce messages (which are seperate emails after all and therefore beyond
the statefulness of the NAT connection).  Best to do your own MTA & use
the ISPs as a "smarthost" (sendmail terminology).  A smarthost is
basically a better connected MTA that you send all your mail to for
subsequent delivery.

[1] The exception, where you can get away with doing the NAT of port 25 is 
where you are redirecting all return mail to a remote mail box anyway, 
such as in the case of a dynamic IP.  Even in this case I prefer not to 
NAT port 25.

Rob

-- Robert Brockway B.Sc. email: robert at timetraveller.org  ICQ: 104781119
   Linux counter project ID #16440 (http://counter.li.org)
   avon: up 17 days, 13:11,  1 user,  load average: 0.00, 0.00, 0.00
   "The earth is but one country and mankind its citizens" -Baha'u'llah


--
* This is list (humbug) general handled by majordomo at lists.humbug.org.au .
* Postings to this list are only accepted from subscribed addresses of
* lists 'general' or 'general-post'.  See http://www.humbug.org.au/



More information about the General mailing list