Re: Routing solution on mail servers with all domain pointing at the same externel IP
Stephen Liu <[email protected]>
| Newsgroups | gmane.mail.perdition.user |
|---|---|
| Message-ID | <[email protected]> |
--- Jimmy Brake <[email protected]> wrote: --------------------------------- Hi, Wow kind of a busy thread so I am not sure if I fully understand it ..however .. the setup looks similar to mine. Where I have differentclients in the same or different domains that need to be routed to theproper server. I remember it was not easy to setup. M /usr/lib/libperditiondb_mysql.so.0 msomeIP:3306:dbPerdition:tblPerdition:dbUser:dbPass:servername:concat(user,\'@\',domain):port server_resp_line Those are pretty much the only three lines in my config file forperdition. You could change these to suite your needs:"someIP:3306:dbPerdition:tblPerdition:dbUser:dbPass" You should probably not change these:"servername:concat(user,\'@\',domain):port" my mysql table looks like this mysql> describe perdition; +------------+--------------+------+-----+---------+-------+ | Field | Type | Null | Key | Default | Extra | +------------+--------------+------+-----+---------+-------+ | user | varchar(128) | NO | MUL | NULL | | | domain | varchar(255) | NO | MUL | NULL | | | servername | varchar(255) | NO | MUL | NULL | | | port | varchar(8) | NO | MUL | NULL | | +------------+--------------+------+-----+---------+-------+ some rows of users mysql> select * from perdition limit 0,10; +------------+----------------+------------------------+------+ | user | domain | servername | port | +------------+----------------+------------------------+------+ | donotreply | dwalliance.com | node8.youdomain.com | | | jimmy | dwalliance.com | node8.youdomain.com | | | inda | dwalliance.com | node8.youdomain.com | | | support | dwalliance.com | node8.youdomain.com | | | costarica | dwalliance.com | node8.youdomain.com | | | cathe | dwalliance.com | node7.youdomain.com | | | node7 | dwalliance.com | node7.youdomain.com | | | node6 | dwalliance.com | node6.youdomain.com | | | donnie | thebrakes.org | node8.youdomain.com | | | ken | brake.org | node8.youdomain.com | | +------------+----------------+------------------------+------+ We left the port blank .. when we had the port set to a protocol itwould only allow that protocol. Leaving it blank and people can usewhatever suits them best. Before any of this will work ... make sure imap / pop work on the mailhosts, make sure the mysql account works from the perdition server. Sorry I did not read through the complete thread and I hope this helps. Jimmy Hi Jimmy, Thanks for your advice. I'll come back to you on my 2nd test, test2 B.R. Stephen L Stephen Liu wrote: --- Gustavo Luiz Duarte <[email protected]> wrote: Well, it worked. Now your courier imap is rejecting the user/pass yousupplied. Hi Gustavo,Yes, it works. I must use the password on the user.table of MySQLmaildb, NOT the password to login the mail server.xen11:~# echo "tag login [email protected] mypasswd" | nc xen11.satimis.com 143* OK [CAPABILITY IMAP4rev1 UIDPLUS CHILDREN NAMESPACETHREAD=ORDEREDSUBJECT THREAD=REFERENCES SORT QUOTA AUTH=CRAM-MD5AUTH=CRAM-SHA1 IDLE ACL ACL2=UNION STARTTLS] Courier-IMAP ready.Copyright 1998-2005 Double Precision, Inc. See COPYING fordistribution information.tag OK LOGIN Ok.xen11:~# tail /var/log/mail.logDec 3 16:27:40 xen11 imapd: LOGIN: ip=[::ffff:192.168.0.211],command=LOGINDec 3 16:27:40 xen11 imapd: LOGIN: ip=[::ffff:192.168.0.211],[email protected] 3 16:27:40 xen11 imapd: LOGIN: ip=[::ffff:192.168.0.211],password=mypasswdDec 3 16:27:40 xen11 authdaemond: received auth request, service=imap,authtype=loginDec 3 16:27:40 xen11 authdaemond: authmysql: trying this moduleDec 3 16:27:40 xen11 authdaemond: SQL query: SELECT id, "", clear,uid, gid, home, concat(home,'/',maildir), "", name, "" FROM users WHEREid = "[email protected]" AND (enabled=1)Dec 3 16:27:40 xen11 authdaemond: authmysql: sysusername=<null>,sysuserid=5000, sysgroupid=5000, homedir=/var/spool/mail/virtual,[email protected], fullname=Stephen,maildir=/var/spool/mail/virtual/Stephen/, quota=<null>, options=<null>Dec 3 16:27:40 xen11 authdaemond: Authenticated: sysusername=<null>,sysuserid=5000, sysgroupid=5000, homedir=/var/spool/mail/virtual,[email protected], fullname=Stephen,maildir=/var/spool/mail/virtual/Stephen/, quota=<null>, options=<null>Dec 3 16:27:40 xen11 imapd: LOGIN, [email protected],ip=[::ffff:192.168.0.211], protocol=IMAPDec 3 16:28:14 xen11 imapd: DISCONNECTED, [email protected],ip=[::ffff:192.168.0.211], headers=0, body=0, rcvd=0, sent=18, time=34With the same password on Evolution I can send mails but can't receivemails.IMAPrev1Server: xen11.satimis.comusername: [email protected] while Scanning folders in "IMAP server xen11.satimis.com".Failed sending command to IMAP server xen11.satimis.com: Interruptedsystem callxen11:~# tail /var/log/mail.logDec 3 17:02:13 xen11 authdaemond: authmysql: sysusername=<null>,sysuserid=5000, sysgroupid=5000, homedir=/var/spool/mail/virtual,[email protected], fullname=Stephen,maildir=/var/spool/mail/virtual/Stephen/, quota=<null>, options=<null>Dec 3 17:02:13 xen11 authdaemond: Authenticated: sysusername=<null>,sysuserid=5000, sysgroupid=5000, homedir=/var/spool/mail/virtual,[email protected], fullname=Stephen,maildir=/var/spool/mail/virtual/Stephen/, quota=<null>, options=<null>Dec 3 17:02:13 xen11 imapd: LOGIN, [email protected],ip=[::ffff:192.168.0.110], protocol=IMAPDec 3 17:03:25 xen11 postfix/anvil[3590]: statistics: max connectionrate 1/60s for (smtp:220.232.213.178) at Dec 3 16:57:27Dec 3 17:03:25 xen11 postfix/anvil[3590]: statistics: max connectioncount 1 for (smtp:220.232.213.178) at Dec 3 16:57:27Dec 3 17:03:25 xen11 postfix/anvil[3590]: statistics: max cache size 1at Dec 3 16:57:27Dec 3 17:05:44 xen11 imapd: DISCONNECTED, [email protected],ip=[::ffff:192.168.0.110], headers=6318, body=0, rcvd=7778, sent=61498,time=211Dec 3 17:05:52 xen11 imapd: Connection, ip=[::ffff:192.168.0.110]Dec 3 17:05:52 xen11 imapd: LOGIN: ip=[::ffff:192.168.0.110],command=CAPABILITYDec 3 17:06:14 xen11 imapd: Disconnected, ip=[::ffff:192.168.0.110],time=22A further question, on remote PC how can remote mail client find theserver-xen11.satimis.com? Use the external IP of the routing mailserver?B.R.Stephen On Thu, Dec 4, 2008 at 01:17, Stephen Liu <[email protected]> wrote: --- Gustavo Luiz Duarte <[email protected]> wrote: I suppose IMAP4_FLAGS="-m /etc/perdition_lookup.gdbm.db --query_key '\d ' " Edit /etc/default/perditionxen11:~# cat /etc/default/perdition | grep IMAP4_FLAGS# by POP3_FLAGS, POP3S_FLAGS, IMAP4_FLAGS or IMAP4S_FLAGSIMAP4_FLAGS="-m /etc/perdition_lookup.gdbm.db --query_key '\d' "xen11:~# /etc/init.d/perdition restartStopped /usr/sbin/perdition.pop3 (pid 3458).No /usr/sbin/perdition.pop3s found running; none killed.No /usr/sbin/perdition.imap4 found running; none killed.No /usr/sbin/perdition.imaps found running; none killed.Starting /usr/sbin/perdition.pop3...Starting /usr/sbin/perdition.pop3s...Starting /usr/sbin/perdition.imap4...Starting /usr/sbin/perdition.imaps...xen11:~# echo "tag login [email protected] mypasswd" | ncxen11.satimis.com 143* OK [CAPABILITY IMAP4rev1 UIDPLUS CHILDREN NAMESPACETHREAD=ORDEREDSUBJECT THREAD=REFERENCES SORT QUOTA AUTH=CRAM-MD5AUTH=CRAM-SHA1IDLE ACL ACL2=UNION STARTTLS] Courier-IMAP ready.Copyright 1998-2005 Double Precision, Inc. See COPYING fordistribution information.tag NO Login failed.hanging here.xen11:~# tail /var/log/mail.logDec 3 15:58:01 xen11 imapd: LOGIN: ip=[::ffff:192.168.0.211],[email protected] 3 15:58:01 xen11 imapd: LOGIN: ip=[::ffff:192.168.0.211],password=mypasswdDec 3 15:58:01 xen11 authdaemond: received auth request, service=imap, authtype=loginDec 3 15:58:01 xen11 authdaemond: authmysql: trying this moduleDec 3 15:58:01 xen11 authdaemond: SQL query: SELECT id, "", clear,uid, gid, home, concat(home,'/',maildir), "", name, "" FROM usersWHERE id = "[email protected]" AND (enabled=1)Dec 3 15:58:01 xen11 authdaemond: supplied password does not matchclearpasswdDec 3 15:58:01 xen11 authdaemond: authmysql: REJECT - try next module Dec 3 15:58:01 xen11 authdaemond: FAIL, all modules rejectedDec 3 15:58:01 xen11 imapd: LOGIN FAILED, [email protected], ip=[::ffff:192.168.0.211]Dec 3 15:58:21 xen11 imapd: Disconnected, ip=[::ffff:192.168.0.211], time=20Still failB.R.Stephen L On Thu, Dec 4, 2008 at 00:30, Stephen Liu <[email protected]> wrote: --- Gustavo Luiz Duarte <[email protected]> wrote: You are not supplying the necessary options: -m and --query_key. You can set it by command line parameter or in/etc/perdition/perdition.conf (maybe /etc/defaults too) Hi Gustavo,Please advise how to set them on /etc/default/perdition.cat /etc/default/perdition ###################################################################### # /etc/sysconfig/perdition (RPM based systems)# /etc/default/perdition (Debian)## Run time configuration parameters for perdition ###################################################################### # Run perdition# Set to "yes" to run perdition# Set to any other value to not run perditionRUN_PERDITION=yes# Command line parameters to pass to perdition when run in any mode. # This is in addition to any mode specific flags.# That is, it is in addtion to any command line options supplied# by POP3_FLAGS, POP3S_FLAGS, IMAP4_FLAGS or IMAP4S_FLAGS#FLAGS=# Run an instance of perdition in POP3 mode# Set to "yes" to run this instance of perdition# Set to any other valye to not run this instance of perditionPOP3=yes#Command line parameters to pass to perdition when run in POP3 mode POP3_FLAGS=# Run an instance of perdition in POP3S mode# Set to "yes" to run this instance of perdition# Set to any other valye to not run this instance of perditionPOP3S=yes#Command line parameters to pass to perdition when run in POP3S mode POP3S_FLAGS=# Run an instance of perdition in IMAP4 mode# Set to "yes" to run this instance of perdition# Set to any other valye to not run this instance of perditionIMAP4=yes#Command line parameters to pass to perdition when run in IMAP4 mode IMAP4_FLAGS=# Run an instance of perdition in IMAP4S mode# Set to "yes" to run this instance of perdition# Set to any other valye to not run this instance of perditionIMAP4S=yes#Command line parameters to pass to perdition when run in IMAP4S mode IMAP4S_FLAGS=* end *TIAB.R.Stephen L For some reason I was thinking about the hints I gave you and realizedI made a mistake. I forgot to mention that your client needs to use the domain while authenticating. So the test would be:$ echo "tag login username@domain password" | nc perdition_host 143 Without the domain (as I had written) perdition cannot resolve which server to connect. Tried again.xen11:~# /etc/init.d/perdition restartStopped /usr/sbin/perdition.pop3 (pid 2878).No /usr/sbin/perdition.pop3s found running; none killed.No /usr/sbin/perdition.imap4 found running; none killed.No /usr/sbin/perdition.imaps found running; none killed./usr/sbin/perdition.pop3 already running.Starting /usr/sbin/perdition.pop3s...Starting /usr/sbin/perdition.imap4...Starting /usr/sbin/perdition.imaps...xen11:~# echo "tag login [email protected] x10satimis" | ncxen11.satimis.com 143* OK [CAPABILITY IMAP4rev1 UIDPLUS CHILDREN NAMESPACETHREAD=ORDEREDSUBJECT THREAD=REFERENCES SORT QUOTA AUTH=CRAM-MD5 AUTH=CRAM-SHA1 IDLE ACL ACL2=UNION STARTTLS] Courier-IMAP ready. Copyright 1998-2005 Double Precision, Inc. See COPYING fordistribution information.tag NO Login failed.Hanging here. I have to exit it manually with [Ctrl]+cxen11:~# tail /var/log/mail.logDec 3 14:37:01 xen11 imapd: LOGIN: ip=[::ffff:192.168.0.211], [email protected] 3 14:37:01 xen11 imapd: LOGIN: ip=[::ffff:192.168.0.211], password=mypasswdDec 3 14:37:01 xen11 authdaemond: received auth request, service=imap, authtype=loginDec 3 14:37:01 xen11 authdaemond: authmysql: trying this module Dec 3 14:37:01 xen11 authdaemond: SQL query: SELECT id, "", clear, uid, gid, home, concat(home,'/',maildir), "", name, "" FROM users WHERE id = "[email protected]" AND (enabled=1)Dec 3 14:37:01 xen11 authdaemond: supplied password does not match clearpasswdDec 3 14:37:01 xen11 authdaemond: authmysql: REJECT - try next module Dec 3 14:37:01 xen11 authdaemond: FAIL, all modules rejectedDec 3 14:37:02 xen11 imapd: LOGIN FAILED, [email protected], ip=[::ffff:192.168.0.211]Dec 3 14:37:20 xen11 imapd: Disconnected, ip=[::ffff:192.168.0.211], time=19Still fail.B.R.Stephen L On Wed, Dec 3, 2008 at 15:49, Gustavo Luiz Duarte<[email protected]> wrote: On Wed, Dec 3, 2008 at 15:27, Stephen Liu <[email protected]> wrote: --- Gustavo Luiz Duarte <[email protected]> wrote: On Wed, Dec 3, 2008 at 12:05, Stephen Liu <[email protected]> wrote: Hi Gustavo,I'll make 2 tests;1)test1 - USING TEXT FILE2)test2 - USING MYSQLI have cloned an image of the routing mail server for test2. Now proceed test1 first.--- Gustavo Luiz Duarte <[email protected]> wrote: Hi Stephen,You could use the transport table if the string "smtp:" wasn't there. Do you really want to use mysql for the lookup? If you have only 3 domain you could use a text file.USING TEXT FILE:$ cat << END > /etc/perdition_lookup.txtsatimis.dnsalias.com:192.168.0.209satimis.changeip.net:192.168.0.208satimis.com:192.168.0.210END$ makegdbm /etc/perdition_lookup.gdbm.db < /etc/perdition_lookup.txt $ perdition -m /etc/perdition_lookup.gdbm.db --query_key "\d" Package installed - perdition-mysql# apt-cache policy perdition-mysqlperdition-mysql: Installed: 1.17-7etch1 Candidate: 1.17-7etch1 Version table: *** 1.17-7etch1 0 500 http://ftp.au.debian.org etch/main Packages 500 http://security.debian.org stable/updates/main Packages 100 /var/lib/dpkg/status# cat << END > /etc/perdition_lookup.txt satimis.dnsalias.com:192.168.0.209satimis.changeip.net:192.168.0.208satimis.com:192.168.0.210END # which makegdbm/usr/bin/makegdbm# which perdition/usr/sbin/perdition# makegdbm /etc/perdition_lookup.gdbm.db < /etc/perdition_lookup.txt # perdition -m /etc/perdition_lookup.gdbm.db --query_key "\d" both without complaintNow I haven't figured out how to test perdition. There are 2 databases running on this routing mail server, MySQL maildb andperdition_lookup.gdbm.db. Do I need to stop MySQL maildb to test perdition? How can the remote mail clients connect their mail servers? What server settings shall I use? Please shed me some light. TIA No need for stopping you MySQL.If everything is wright (I haven't tested, I can have skipped something), you can point your mail clients to the hostname where perdition is installed and use it normally. Sorry I can't resolve how can the mail client (Evolution) find its server over Internet with following settings; The mail client doesn't know wich server to use. It always use the routing server. The routing server redirects it to the correct imap server. Make sure your are using the right protocol imap4 or imap4s. Server Type: IMAPServer : xen11.satimis.com (hostname of the routing mail server where perdition is runningUser: satimissatimis is user of satimis.com, satimis.changeip.net andsatimis.dnsalias.com as well as user of the routing mail server, xen11.satimis.comI tried it without success. Note that perdition's default protocol is pop3. To use imap suply the option -P IMAP4 xen11:~# /etc/init.d/perdition start/usr/sbin/perdition.pop3 already running.Starting /usr/sbin/perdition.pop3s...Starting /usr/sbin/perdition.imap4...Starting /usr/sbin/perdition.imaps... How are you configuring perdition? Have you modified your/etc/init.d/perdition script to contain the correct parameters? xen11:~# hostnamexen11.satimis.compop3 is already running. I have to manually run /etc/init.d/perdition to start pop3s, imap4 and imaps You can use nc to test it:$ echo "tag login username password" | nc perdition_host 143 In username and password you use valid username and password for your real imap server. I suppose running above command on the routing mail server where perdition is installed.# echo "tag login satimis mypassword" | nc xen11.satimis.com 143 * OK [CAPABILITY IMAP4rev1 UIDPLUS CHILDREN NAMESPACETHREAD=ORDEREDSUBJECT THREAD=REFERENCES SORT QUOTA AUTH=CRAM-MD5 AUTH=CRAM-SHA1 IDLE ACL ACL2=UNION STARTTLS] Courier-IMAP ready. Copyright 1998-2005 Double Precision, Inc. See COPYING fordistribution information.tag NO Login failed. For pop3:$ echo -e "user username\npass password | nc perdition_host 110 xen11:~# echo -e "user satimis\npass x11satimis | nc xen11.satimis.com 110 waiting for input You can look at perdition logs to find information about what is going on. No special configuration is need for your pop/imap servers. Just assure that they are listening on standard ports. I have only ONE external IP. All ports are forwarded to the routing mail server except port 53.B.R.Stephen L []'sGustavo Duarte B.R.Stephen USING MYSQL:You have some alternatives:1. Continue with your tblPerdition and populate it, so that user column has the domain, hostname column has the localIP and port columnyou leave empty (supposing your real pop/imap servers listen to standard ports).Then you would do (supposing you have mysql perdition library in /usr/lib):perdition -M /usr/lib/libperditiondb_mysql.so.0 --query_key "\d" -m "<dbhost>:<dbport>:dbPerdition:tblPerdition:perdition:perdition" (substituting <dbhost> and <dbport> by you db hostname and port) 2. Modify your transport table so that the string smtp and localIP arein diferent columns. Then you create a view concatenating them for thepostfix query. A bit more complicated but easier to maintain when you have lots of domains and servers.[]'sGustavo DuarteOn Wed, Dec 3, 2008 at 02:28, Stephen Liu <[email protected]> wrote: Hi Gustavo, The URL I sent you has information about using mysql as lookup library: http://www.vergenet.net/linux/perdition/perditiondb.5.shtml I suppose you're referring to following section;MYSQLThis map library can be used by specifying the full path to the library using the -M|--map_library command line option or configuration file option.E.g.perdition -M /usr/lib/libperditiondb_mysql.so.0......I'll start from there.I suppose the name of this database is "dbPerdition" to be created on MySQLmysql> create database dbPerdition;mysql> GRANT SELECT,INSERT,UPDATE,DELETE,CREATE,DROP -> ON dbPerdition.* TO 'perdition' IDENTIFIED by 'perdition'; the 1st "perdition" on above second line is "database user". The 2nd "perdition" is "database password".mysql> CREATE TABLE `tblPerdition` ( -> `user` varchar(128), null '' default '', -> `servername` varchar(255) null '' default '', -> `port` varchar(8) YES NULL, -> PRIMARY KEY (`user`), -> ) ;Afterwards I'll edit data on 'tblPerdition" table. The table you've shown doesn't have information about the hostnames/localIPs. Where is it? In the transport table? Yes.mysql> SELECT * from transport; +------+----------------------+--------------------+-----------+---------+ | pkid | domain | hostname | transport | enabled | +------+----------------------+--------------------+-----------+---------+ | 1 | satimis.dnsalias.com | smtp:192.168.0.209 | :[] | 1 || 2 | satimis.changeip.net | smtp:192.168.0.208 | :[] | 1 || 3 | satimis.com | smtp:192.168.0.210 | :[] | 1 | +------+----------------------+--------------------+-----------+---------+ 3 rows in set (0.00 sec)# cat /etc/postfix/mysql_transport_maps.cfuser=mailpassword=mypassworddbname=maildbtable=transportselect_field=hostnamewhere_field=domainhosts=127.0.0.1additional_conditions = and enabled = 1* end * I've never used mysql to do it, so I don't know the details and how flexible it is. Maybe you'll need to create a view in your database for the perdition lookup with the domain as key and the localIP as value.Unfortunately I don't have any example. But the two URLs I sent you have all information you need. In particular, look at --query_key option and mysql database access library. Whether you meant "--query_key FORMAT[,FORMAT...]:" on; http://www.vergenet.net/linux/perdition/perdition.8.shtml ThanksB.R.Stephen LSend instant messages to your online friends http://uk.messenger.yahoo.com ______________________________________________Perdition-users mailing [email protected]://lists.vergenet.net/listinfo/perdition-users Send instant messages to your online friends http://uk.messenger.yahoo.com ______________________________________________Perdition-users mailing [email protected]://lists.vergenet.net/listinfo/perdition-users Send instant messages to your online friends http://uk.messenger.yahoo.com ______________________________________________Perdition-users mailing [email protected]://lists.vergenet.net/listinfo/perdition-users Send instant messages to your online friends http://uk.messenger.yahoo.com ______________________________________________Perdition-users mailing [email protected]://lists.vergenet.net/listinfo/perdition-users Send instant messages to your online friends http://uk.messenger.yahoo.com ______________________________________________Perdition-users mailing [email protected]://lists.vergenet.net/listinfo/perdition-users Send instant messages to your online friends http://uk.messenger.yahoo.com ______________________________________________Perdition-users mailing [email protected]://lists.vergenet.net/listinfo/perdition-users Send instant messages to your online friends http://uk.messenger.yahoo.com ______________________________________________Perdition-users mailing [email protected]://lists.vergenet.net/listinfo/perdition-users > ______________________________________________ > Perdition-users mailing list > [email protected] > http://lists.vergenet.net/listinfo/perdition-users > Send instant messages to your online friends http://uk.messenger.yahoo.com ______________________________________________ Perdition-users mailing list [email protected] http://lists.vergenet.net/listinfo/perdition-users