Kommunikationsproblem mit Gmail

Patrick Ben Koetter p at sys4.de
Mi Nov 4 14:10:55 CET 2015


Sieht im Log so aus als hättest Du die tlsproxy und dnsblog services in
der master.cf nicht aktiviert.

Am 04.11.2015 um 14:07 schrieb Tim-Ole:
> Hallo, Liste,
>
> ich hoffe, es ist nichts zu triviales, das ich hier übersehen habe … aber seit der Umstellung auf ein neues Mailgateway mit Postscreen kommen Mails von Gmail / Googlemail-Adressen nicht an.
>
> Die Meldung im Postfixlog ist dann immer in etwa so:
>
> Nov  3 21:16:53 mailin postfix/postscreen[25029]: CONNECT from [209.85.214.170]:33984 to [1.2.3.4]:25
> Nov  3 21:16:53 mailin postfix/postscreen[25029]: warning: psc_dnsbl_request: connect to private/dnsblog service: Connection refused
> Nov  3 21:16:58 mailin postfix/postscreen[25029]: CONNECT from [209.85.192.48]:36646 to [1.2.3.4]:25
> Nov  3 21:16:58 mailin postfix/postscreen[25029]: warning: psc_dnsbl_request: connect to private/dnsblog service: Connection refused
> Nov  3 21:16:59 mailin postfix/postscreen[25029]: warning: connect to private/tlsproxy service: No such file or directory
> Nov  3 21:16:59 mailin postfix/postscreen[25029]: HANGUP after 0.36 from [209.85.214.170]:33984 in tests after SMTP handshake
> Nov  3 21:16:59 mailin postfix/postscreen[25029]: DISCONNECT [209.85.214.170]:33984
> Nov  3 21:17:05 mailin postfix/postscreen[25029]: warning: connect to private/tlsproxy service: No such file or directory
> Nov  3 21:17:05 mailin postfix/postscreen[25029]: HANGUP after 0.3 from [209.85.192.48]:36646 in tests after SMTP handshake
> Nov  3 21:17:05 mailin postfix/postscreen[25029]: DISCONNECT [209.85.192.48]:36646
> Nov  3 21:17:35 mailin postfix/postscreen[25029]: CONNECT from [46.234.228.26]:46532 to [1.2.3.4]:25
> Nov  3 21:17:35 mailin postfix/postscreen[25029]: warning: psc_dnsbl_request: connect to private/dnsblog service: Connection refused
> Nov  3 21:17:41 mailin postfix/postscreen[25029]: NOQUEUE: reject: RCPT from [46.234.228.26]:46532: 450 4.3.2 Service currently unavailable; from=<ms-F7761B258E37141A029EA2B40BC32926ABF1C6D2F1651D52B2AAF262978794F15C0823 at bounce.mmdlv.it>, to=<info at unser-server.de>, proto=ESMTP, helo=<mts102f.dem.oemts.net>
> Nov  3 21:17:41 mailin postfix/postscreen[25029]: PASS NEW [46.234.228.26]:46532
> Nov  3 21:17:41 mailin postfix/postscreen[25029]: DISCONNECT [46.234.228.26]:46532
>
> Es gibt also einen Hangup des Gmailservers um diese beiden Meldungen:
>
> warning: psc_dnsbl_request: connect to private/dnsblog service: Connection refused
> warning: connect to private/tlsproxy service: No such file or directory
>
> = und wohlgemerkt NUR mit Zustellversuchen von Gmailservern … alles andere kommt - soweit ich es sehe - problemlos an.
>
> Irgendwie verstehen sich offenbar Postscreen und Gmail nicht - aber ich finde nichts, wie ich das abstellen kann :\
>
> Momentan behelfen wir uns mit dem Freischalten der Gmail-MX-IPs, aber so richtig befriedigend ist das ja auch nicht …
>
> Vielen Dank im Voraus für Tipps!
>
> Schöne Grüße
>
> toag
>
>
> Infos:
>
>
> OS: Debian 7
> Postfix = 2.9.6
>
> main.cf:
>
> soft_bounce = no
> (…)
> mydestination = 
>   $myhostname
>   localhost.localdomain
>   localhost
>
> relay_recipient_maps = 
> smtpd_restriction_classes = restrictive, permissive
> restrictive = reject_unverified_recipient
> permissive = permit
> mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128
> alias_maps = hash:/etc/aliases
> alias_database = hash:/etc/aliases
> virtual_transport = virtual
> virtual_maps = hash:/etc/postfix/virtual
> smtpd_use_tls                 = yes
> smtpd_tls_loglevel            = 3
> smtpd_tls_received_header     = yes
> smtpd_tls_security_level      = may
> smtpd_tls_cert_file           = /etc/ssl/private/mailin.foo.it/selfmail.cert
> smtpd_tls_key_file            = /etc/ssl/private/mailin.foo.it/selfmail.key
> smtpd_tls_CAfile              = /etc/ssl/certs/ca.pem
> smtpd_tls_auth_only           = no
> smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
> smtpd_tls_session_cache_timeout = 3600s
> tls_random_source = dev:/dev/urandom
> tls_random_prng_update_period = 3600s
> smtpd_tls_CApath = /etc/ssl/certs
> smtpd_helo_required = yes
> smtpd_sender_restrictions =
>   permit_mynetworks
>   check_sender_access hash:/etc/postfix/sender_access
>   reject_unlisted_sender
>   reject_unknown_sender_domain
> smtpd_recipient_restrictions = permit_sasl_authenticated
>   permit_mynetworks
>   check_recipient_access hash:/etc/postfix/verify_domains
>   check_client_access hash:/etc/postfix/check_client_access
>   check_policy_service inet:127.0.0.1:10023
>   reject_unknown_recipient_domain
>   reject_unknown_helo_hostname
>   reject_unknown_reverse_client_hostname
>   reject_unauth_destination
>   check_policy_service inet:127.0.0.1:12525
>   permit
> smtpd_data_restrictions = reject_unauth_pipelining,
> 	permit
> postscreen_access_list = permit_mynetworks,
> 	cidr:/etc/postfix/postscreen_access.cidr
> postscreen_blacklist_action = drop
> postscreen_dnsbl_threshold = 3
> postscreen_dnsbl_sites = zen.spamhaus.org
> postscreen_dnsbl_action = enforce
> postscreen_greet_banner = $smtpd_banner
> postscreen_greet_action = enforce
> postscreen_bare_newline_enable = no
> postscreen_non_smtp_command_enable = yes
> postscreen_non_smtp_command_action = drop
> postscreen_pipelining_enable = no
> mailbox_size_limit = 0
> message_size_limit = 25480000
> recipient_delimiter = +
> inet_interfaces = all
> default_transport = smtp
> relay_transport = smtp
> transport_maps = hash:/etc/postfix/transport
>
> master.cf
> smtp      inet  n       -       n       -       1       postscreen
> smtpd     pass  -       -       -       -       -       smtpd
> smtp-amavis unix -      -       y     -       2  smtp
>     -o smtp_data_done_timeout=1200
>     -o smtp_send_xforward_command=yes
>     -o disable_dns_lookups=yes
>     -o max_use=20
> 127.0.0.1:10025 inet n  -       y     -       -  smtpd
>     -o content_filter=
>     -o local_recipient_maps=
>     -o relay_recipient_maps=
>     -o smtpd_restriction_classes=
>     -o smtpd_delay_reject=no
>     -o smtpd_client_restrictions=permit_mynetworks,reject
>     -o smtpd_helo_restrictions=
>     -o smtpd_sender_restrictions=
>     -o smtpd_recipient_restrictions=permit_mynetworks,reject
>     -o smtpd_data_restrictions=reject_unauth_pipelining
>     -o smtpd_end_of_data_restrictions=
> 	-o smtpd_end_of_data_restrictions=
>     -o mynetworks=127.0.0.0/8
>     -o smtpd_error_sleep_time=0
>     -o smtpd_soft_error_limit=1001
>     -o smtpd_hard_error_limit=1000
>     -o smtpd_client_connection_count_limit=0
>     -o smtpd_client_connection_rate_limit=0
>     -o receive_override_options=no_header_body_checks,no_unknown_recipient_checks
> dovecot   unix  -       n       n       -       -       pipe
>     flags=DRhu user=vmail:mail argv=/usr/lib/dovecot/deliver -d ${recipient}
> pickup    fifo  n       -       -       60      1       pickup
> cleanup   unix  n       -       -       -       0       cleanup
> qmgr      fifo  n       -       -       300     1       qmgr
> rewrite   unix  -       -       -       -       -       trivial-rewrite
> bounce    unix  -       -       -       -       0       bounce
> defer     unix  -       -       -       -       0       bounce
> trace     unix  -       -       -       -       0       bounce
> verify    unix  -       -       -       -       1       verify
> flush     unix  n       -       -       1000?   0       flush
> proxymap  unix  -       -       n       -       -       proxymap
> smtp      unix  -       -       -       -       -       smtp
> relay     unix  -       -       -       -       -       smtp
> showq     unix  n       -       -       -       -       showq
> error     unix  -       -       -       -       -       error
> local     unix  -       n       n       -       -       local
> virtual   unix  -       n       n       -       -       virtual
> lmtp      unix  -       -       n       -       -       lmtp
> anvil     unix  -       -       n       -       1       anvil
> maildrop  unix  -       n       n       -       -       pipe
>   flags=DRhu user=vmail argv=/usr/local/bin/maildrop -d ${recipient}
> uucp      unix  -       n       n       -       -       pipe
>   flags=Fqhu user=uucp argv=uux -r -n -z -a$sender - $nexthop!rmail ($recipient)
> ifmail    unix  -       n       n       -       -       pipe
>   flags=F user=ftn argv=/usr/lib/ifmail/ifmail -r $nexthop ($recipient)
> bsmtp     unix  -       n       n       -       -       pipe
>   flags=Fq. user=bsmtp argv=/usr/lib/bsmtp/bsmtp -d -t$nexthop -f$sender $recipient
> scalemail-backend unix	-	n	n	-	2	pipe
>   flags=R user=scalemail argv=/usr/lib/scalemail/bin/scalemail-store ${nexthop} ${user} ${extension}
> tlsmgr    unix  -       -       -       1000?   1       tlsmgr
>
>

-- 
[*] sys4 AG
https://sys4.de, +49 (89) 30 90 46 64
Franziskanerstraße 15, 81669 München
Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263
Vorstand: Patrick Ben Koetter, Marc Schiffbauer
Aufsichtsratsvorsitzender: Florian Kirstein


-------------- nächster Teil --------------
Ein Dateianhang mit Binärdaten wurde abgetrennt...
Dateiname   : smime.p7s
Dateityp    : application/pkcs7-signature
Dateigröße  : 4209 bytes
Beschreibung: S/MIME Cryptographic Signature
URL         : <https://listi.jpberlin.de/pipermail/postfixbuch-users/attachments/20151104/2a13e5da/attachment.p7s>


Mehr Informationen über die Mailingliste Postfixbuch-users