See the content

pfSense releasing the departure of emails to external providers

Posts in the series pfSense and e-mail traffic from internal network

  1. pfSense blocking traffic from email (spammers) from the internal network
  2. pfSense releasing the departure of emails to external providers

Following the previous text on the blocking of access to the SMTP client's internal network by using the pfSense, today we know how to make access to SMTP and others to an external provider specific. SMTP blocking traffic to the outside world is an effective measure to avoid problems, but on the other hand we have legitimate customers who need to access their accounts on our network. So we need to create rules that selectively release the traffic.

The principle is the same, but we know the use of the alias pfsese that provides a better management of networks, protocols and clients with whom we work. To create an alias on the menu pfsense "Firewall" -> "Alias." On the screen of "Alias" (Figure 1) by clicking the icon and the symbol of plus (+) in the upper right corner of your screen to add a new alias (add a new alias). We can create alias for networks, hosts or ports, each alias should one or more IP or port. The great advantage of alias is that if an internal IP or change the door of a service, for example, need not touch any of the firewall rule, just change your alias. For those who manage firewalls with hundreds of rules that is crucial. In our example we will create an alias for Gmail SMTP, which has two IPs working so balanced. On the screen to create the alias (Figure 2) fill the following fields: Name = SMTP_GOOGLE (must be unique and contain only characters and numbers), Description = smtp.gmail.com (This description is not mandatory), Type = Host (s ) And IPs. To add more IPs and their descriptions simply click on the button with the symbol of plus (+) in the lower left corner of the screen (see Figure 2). Then save the alias by clicking the "Save". We must implement the changes to begin functioning immediately. To activate the changes just click the "Apply changes" that automatically appears in a box at the top of the list of aliases. There already have our pro alias Gmail SMTP, if Google change the future, or add new IPs just change the alias .

We will now rule for the creation of free traffic to Gmail. The menu "Firewall" -> "Rules", then click on the tab LAN, we want to include a rule that frees the traffic on our internal network to Gmail. On the screen of rules for the LAN click on the icon with the symbol of plus (+) in the upper right corner of the screen (add new rule). On the next screen (Figure 3) Edit the new rule by filling out the following fields: Action = Pass (default) and Destination (Type: Single host or alias) = SMTP_GOOGLE, Destination port range (from and to any: any) and Any description = -> Gmaill. This field is only a description and can be any descriptive text. The other fields are with the default values, it is not necessary to change them. After ready just click on "Save" to save the rule, the rule is stored must implement the changes so as to work immediately. To apply the changes (reload the rules) is just click the "Apply changes" that automatically appears in a box at the top of the list of rules. Similar to obstruct the SMTP standard can lock on the door or release other protocols / ports using the same steps explained here, obviously with necessary adjustments.

It is important to note that the firewall rules are applied from above to get down (which appears at the top of the list has priority over the second rule, and so on). To change the position between the rules just use the arrow button in the form of (<=) which is in front of the rule, which makes up the rule, applied after the mundanças already be worth.

(Click on pictures to enlarge them)


tela alias pfsense

Figure 1: Display the alias pfsense


cria alias no pfsense

Figure 2: Creating new alias on pfsense


criação de regra no pfsense para o gmail

Figure 3: creating new rule firewall with the alias


listagem de regras do pfsense

Figure 4: listing of the rules Firewall psfsense


tela de regras - alias no detalhe

Figure 5: detail of the alias being used in the rules of pfsense




BuscaPé, leader compared to prices in Latin America

Also read:

3 Comments

  1. Neli p saints

    Dude ...., Its very good tips, I am trying to configure it, so he limited the download on the network,
    mainly the P2P -> there in TRAFFIC SHAPE, but I live the traffic shapper, I can not bear
    surf the Internet, both of which are slow, I do with it ????? for example the Internet 1mega ..
    What is the ideal rate for download and upload that not panic surfing the Internet and other things
    Only basic ... .. I limit the P2P and games if you like ...

    att. neli p saints
    ps. ps. I need some help urgentimente ..

    Permalink Published on 25-Jul-08 at 15:40 | Permalink
  2. wasare

    Neli,

    We have not had the opportunity to configure control psfsense the bands. About the little I read about the documentation indicates always use the wizard to do the initial configuration. Another thing is that the new 1.3 version to be released soon will count a much improved control of bandwidth. You can track the progress of the development and launch of this fantastic tool directly on the blog of the developers (http://blog.pfsense.org). Another thing in the forum you'll also find tips and information very important.

    Permalink Published on 25-Jul-08 at 21:04 | Permalink
  3. Neli p saints

    Dear Wasare, sorry I bother you again, as has, by chance you do a test of how
    I make the control of bandwidth in pfsense, because I could not, I start it, but I am stating
    too this, my head will roll. patterns in the rules that I activated it makes browsing the Internet or
    I used the wizard traffic shaper to give low priority to P2P and also wanted to limit the download
    Browser door at 80: so for example DOWNLOADS 30Kbps and upload 30kbps eg
    ips for the local network: 192.168.0.10, 192.168.0.11 and so on.

    Respectfully.

    Neli p saints

    Permalink Published on 30-Jul-08 at 14:22 | Permalink

Submit a Comment

Your email will never be published or disclosed to third parties. Required fields are marked *