Kommunikationsproblem mit Gmail
Patrick Ben Koetter
p at sys4.de
Mi Nov 4 14:10:55 CET 2015
Sieht im Log so aus als hättest Du die tlsproxy und dnsblog services in
der master.cf nicht aktiviert.
Am 04.11.2015 um 14:07 schrieb Tim-Ole:
> Hallo, Liste,
>
> ich hoffe, es ist nichts zu triviales, das ich hier übersehen habe … aber seit der Umstellung auf ein neues Mailgateway mit Postscreen kommen Mails von Gmail / Googlemail-Adressen nicht an.
>
> Die Meldung im Postfixlog ist dann immer in etwa so:
>
> Nov 3 21:16:53 mailin postfix/postscreen[25029]: CONNECT from [209.85.214.170]:33984 to [1.2.3.4]:25
> Nov 3 21:16:53 mailin postfix/postscreen[25029]: warning: psc_dnsbl_request: connect to private/dnsblog service: Connection refused
> Nov 3 21:16:58 mailin postfix/postscreen[25029]: CONNECT from [209.85.192.48]:36646 to [1.2.3.4]:25
> Nov 3 21:16:58 mailin postfix/postscreen[25029]: warning: psc_dnsbl_request: connect to private/dnsblog service: Connection refused
> Nov 3 21:16:59 mailin postfix/postscreen[25029]: warning: connect to private/tlsproxy service: No such file or directory
> Nov 3 21:16:59 mailin postfix/postscreen[25029]: HANGUP after 0.36 from [209.85.214.170]:33984 in tests after SMTP handshake
> Nov 3 21:16:59 mailin postfix/postscreen[25029]: DISCONNECT [209.85.214.170]:33984
> Nov 3 21:17:05 mailin postfix/postscreen[25029]: warning: connect to private/tlsproxy service: No such file or directory
> Nov 3 21:17:05 mailin postfix/postscreen[25029]: HANGUP after 0.3 from [209.85.192.48]:36646 in tests after SMTP handshake
> Nov 3 21:17:05 mailin postfix/postscreen[25029]: DISCONNECT [209.85.192.48]:36646
> Nov 3 21:17:35 mailin postfix/postscreen[25029]: CONNECT from [46.234.228.26]:46532 to [1.2.3.4]:25
> Nov 3 21:17:35 mailin postfix/postscreen[25029]: warning: psc_dnsbl_request: connect to private/dnsblog service: Connection refused
> Nov 3 21:17:41 mailin postfix/postscreen[25029]: NOQUEUE: reject: RCPT from [46.234.228.26]:46532: 450 4.3.2 Service currently unavailable; from=<ms-F7761B258E37141A029EA2B40BC32926ABF1C6D2F1651D52B2AAF262978794F15C0823 at bounce.mmdlv.it>, to=<info at unser-server.de>, proto=ESMTP, helo=<mts102f.dem.oemts.net>
> Nov 3 21:17:41 mailin postfix/postscreen[25029]: PASS NEW [46.234.228.26]:46532
> Nov 3 21:17:41 mailin postfix/postscreen[25029]: DISCONNECT [46.234.228.26]:46532
>
> Es gibt also einen Hangup des Gmailservers um diese beiden Meldungen:
>
> warning: psc_dnsbl_request: connect to private/dnsblog service: Connection refused
> warning: connect to private/tlsproxy service: No such file or directory
>
> = und wohlgemerkt NUR mit Zustellversuchen von Gmailservern … alles andere kommt - soweit ich es sehe - problemlos an.
>
> Irgendwie verstehen sich offenbar Postscreen und Gmail nicht - aber ich finde nichts, wie ich das abstellen kann :\
>
> Momentan behelfen wir uns mit dem Freischalten der Gmail-MX-IPs, aber so richtig befriedigend ist das ja auch nicht …
>
> Vielen Dank im Voraus für Tipps!
>
> Schöne Grüße
>
> toag
>
>
> Infos:
>
>
> OS: Debian 7
> Postfix = 2.9.6
>
> main.cf:
>
> soft_bounce = no
> (…)
> mydestination =
> $myhostname
> localhost.localdomain
> localhost
>
> relay_recipient_maps =
> smtpd_restriction_classes = restrictive, permissive
> restrictive = reject_unverified_recipient
> permissive = permit
> mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128
> alias_maps = hash:/etc/aliases
> alias_database = hash:/etc/aliases
> virtual_transport = virtual
> virtual_maps = hash:/etc/postfix/virtual
> smtpd_use_tls = yes
> smtpd_tls_loglevel = 3
> smtpd_tls_received_header = yes
> smtpd_tls_security_level = may
> smtpd_tls_cert_file = /etc/ssl/private/mailin.foo.it/selfmail.cert
> smtpd_tls_key_file = /etc/ssl/private/mailin.foo.it/selfmail.key
> smtpd_tls_CAfile = /etc/ssl/certs/ca.pem
> smtpd_tls_auth_only = no
> smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
> smtpd_tls_session_cache_timeout = 3600s
> tls_random_source = dev:/dev/urandom
> tls_random_prng_update_period = 3600s
> smtpd_tls_CApath = /etc/ssl/certs
> smtpd_helo_required = yes
> smtpd_sender_restrictions =
> permit_mynetworks
> check_sender_access hash:/etc/postfix/sender_access
> reject_unlisted_sender
> reject_unknown_sender_domain
> smtpd_recipient_restrictions = permit_sasl_authenticated
> permit_mynetworks
> check_recipient_access hash:/etc/postfix/verify_domains
> check_client_access hash:/etc/postfix/check_client_access
> check_policy_service inet:127.0.0.1:10023
> reject_unknown_recipient_domain
> reject_unknown_helo_hostname
> reject_unknown_reverse_client_hostname
> reject_unauth_destination
> check_policy_service inet:127.0.0.1:12525
> permit
> smtpd_data_restrictions = reject_unauth_pipelining,
> permit
> postscreen_access_list = permit_mynetworks,
> cidr:/etc/postfix/postscreen_access.cidr
> postscreen_blacklist_action = drop
> postscreen_dnsbl_threshold = 3
> postscreen_dnsbl_sites = zen.spamhaus.org
> postscreen_dnsbl_action = enforce
> postscreen_greet_banner = $smtpd_banner
> postscreen_greet_action = enforce
> postscreen_bare_newline_enable = no
> postscreen_non_smtp_command_enable = yes
> postscreen_non_smtp_command_action = drop
> postscreen_pipelining_enable = no
> mailbox_size_limit = 0
> message_size_limit = 25480000
> recipient_delimiter = +
> inet_interfaces = all
> default_transport = smtp
> relay_transport = smtp
> transport_maps = hash:/etc/postfix/transport
>
> master.cf
> smtp inet n - n - 1 postscreen
> smtpd pass - - - - - smtpd
> smtp-amavis unix - - y - 2 smtp
> -o smtp_data_done_timeout=1200
> -o smtp_send_xforward_command=yes
> -o disable_dns_lookups=yes
> -o max_use=20
> 127.0.0.1:10025 inet n - y - - smtpd
> -o content_filter=
> -o local_recipient_maps=
> -o relay_recipient_maps=
> -o smtpd_restriction_classes=
> -o smtpd_delay_reject=no
> -o smtpd_client_restrictions=permit_mynetworks,reject
> -o smtpd_helo_restrictions=
> -o smtpd_sender_restrictions=
> -o smtpd_recipient_restrictions=permit_mynetworks,reject
> -o smtpd_data_restrictions=reject_unauth_pipelining
> -o smtpd_end_of_data_restrictions=
> -o smtpd_end_of_data_restrictions=
> -o mynetworks=127.0.0.0/8
> -o smtpd_error_sleep_time=0
> -o smtpd_soft_error_limit=1001
> -o smtpd_hard_error_limit=1000
> -o smtpd_client_connection_count_limit=0
> -o smtpd_client_connection_rate_limit=0
> -o receive_override_options=no_header_body_checks,no_unknown_recipient_checks
> dovecot unix - n n - - pipe
> flags=DRhu user=vmail:mail argv=/usr/lib/dovecot/deliver -d ${recipient}
> pickup fifo n - - 60 1 pickup
> cleanup unix n - - - 0 cleanup
> qmgr fifo n - - 300 1 qmgr
> rewrite unix - - - - - trivial-rewrite
> bounce unix - - - - 0 bounce
> defer unix - - - - 0 bounce
> trace unix - - - - 0 bounce
> verify unix - - - - 1 verify
> flush unix n - - 1000? 0 flush
> proxymap unix - - n - - proxymap
> smtp unix - - - - - smtp
> relay unix - - - - - smtp
> showq unix n - - - - showq
> error unix - - - - - error
> local unix - n n - - local
> virtual unix - n n - - virtual
> lmtp unix - - n - - lmtp
> anvil unix - - n - 1 anvil
> maildrop unix - n n - - pipe
> flags=DRhu user=vmail argv=/usr/local/bin/maildrop -d ${recipient}
> uucp unix - n n - - pipe
> flags=Fqhu user=uucp argv=uux -r -n -z -a$sender - $nexthop!rmail ($recipient)
> ifmail unix - n n - - pipe
> flags=F user=ftn argv=/usr/lib/ifmail/ifmail -r $nexthop ($recipient)
> bsmtp unix - n n - - pipe
> flags=Fq. user=bsmtp argv=/usr/lib/bsmtp/bsmtp -d -t$nexthop -f$sender $recipient
> scalemail-backend unix - n n - 2 pipe
> flags=R user=scalemail argv=/usr/lib/scalemail/bin/scalemail-store ${nexthop} ${user} ${extension}
> tlsmgr unix - - - 1000? 1 tlsmgr
>
>
--
[*] sys4 AG
https://sys4.de, +49 (89) 30 90 46 64
Franziskanerstraße 15, 81669 München
Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263
Vorstand: Patrick Ben Koetter, Marc Schiffbauer
Aufsichtsratsvorsitzender: Florian Kirstein
-------------- nächster Teil --------------
Ein Dateianhang mit Binärdaten wurde abgetrennt...
Dateiname : smime.p7s
Dateityp : application/pkcs7-signature
Dateigröße : 4209 bytes
Beschreibung: S/MIME Cryptographic Signature
URL : <https://listi.jpberlin.de/pipermail/postfixbuch-users/attachments/20151104/2a13e5da/attachment.p7s>
Mehr Informationen über die Mailingliste Postfixbuch-users