I've got a mail relay in the DMZ relaying mail to a mail server in the
internal network. In order to do this I've pierced a hole (port 25) to
allow the relay server to contact the internal mail server (and this
server only).
However, I've always heard that it's better not to allow any access from
the DMZ to the LAN, so I was figuring if there might be a way to "pull"
the mail from the DMZ to the LAN.
Does anybody have any comments on this?
The servers in the above scenario are running OpenBSD+postfix (DMZ) and
Linux+sendmail (LAN).
Best regards,
Allan
Sent via Deja.com
http://www.deja.com/