From owner-freebsd-ipfw@FreeBSD.ORG Fri Aug 6 22:51:32 2004 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1944016A4CE for ; Fri, 6 Aug 2004 22:51:32 +0000 (GMT) Received: from andrea.pop4.net (skidway.pop4.net [216.234.109.11]) by mx1.FreeBSD.org (Postfix) with SMTP id 8509F43D48 for ; Fri, 6 Aug 2004 22:51:31 +0000 (GMT) (envelope-from vev@michvhf.com) Received: (qmail 10363 invoked by uid 1008); 6 Aug 2004 22:51:26 -0000 Received: from vev@michvhf.com by www.pop4.net with qmail-scanner-0.96 (uvscan: v4.1.40/v4156. . Clean. Processed in 0.953216 secs); 06 Aug 2004 22:51:26 -0000 Received: from unknown (HELO paprika.michvhf.com) (67.36.71.182) by 0 with SMTP; 6 Aug 2004 22:51:25 -0000 Received: (qmail 39778 invoked by uid 1001); 6 Aug 2004 22:51:31 -0000 Date: Fri, 6 Aug 2004 18:51:31 -0400 (EDT) From: Vince Vielhaber To: Forrest Aldrich In-Reply-To: <411406D7.2000808@forrie.com> Message-ID: References: <411406D7.2000808@forrie.com> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: freebsd-ipfw@freebsd.org Subject: Re: Blocking SMTP traffic based upon RBL.... X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 06 Aug 2004 22:51:32 -0000 On Fri, 6 Aug 2004, Forrest Aldrich wrote: > There are probably dangerous consequences to doing something like this > improperly; however, there is a project out there called PacketBL: > > http://wiki.duskglow.com/index.php/Packetbl > > It's for Linux only, unfortunately -- however I like the idea. It > interfaces with the packet filtering system and selectively blocks SMTP > (port 25, configurable) traffic based upon RBLs etc. > > I wonder if there is a similar way to accomplish this with FreeBSD/ipfw... This works with qmail and any (unixish) OS: http://cr.yp.to/ucspi-tcp/rblsmtpd.html It's part of the ucspi-tcp package. I've been using it since sometime around '98 without a problem. Been using qmail even longer, no problem there either. Vince. -- Fast, inexpensive internet service 56k and beyond! http://www.pop4.net/ http://www.meanstreamradio.com http://www.unknown-artists.com Online radio: It's not file sharing, it's just radio.