Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

GWIA Open Relay won't close 1

Status
Not open for further replies.

JohnMpls

MIS
Oct 3, 2001
4
US
Our ISP claims that we have an SMTP open relay -- they are able to send mail to themselves through our server. They have blacklisted us internally, but so far MAPS et al have not blacklisted us.
This is Groupwise 5.5.4 on Netware 5.0 SP5
Have taken several steps, per Novell's TID's (including 10061682, 10058841) and mail-abuse.org ( including the following:

* In GWIA.CFG file, manually added switch "/NOROUTING"
* in nwadmin, changed to "prevent message relaying" in the SMTP relay settings
* patched the GWIA files up to fgwiad.exe, which are dated September 2001
* rebuilt the GWIA access database (GWAC.DB)

Questions:
gwia.cfg “is not intended to be edited manually,” but I had already done that for other reasons months ago. Does having edited this manually neutralize changes made from nwadmin? Should gwia.cfg be deleted and re-built?

Re-started the GWIA and all Groupwise NLM’s, but does server need to be re-started for changes to be fully effective?

Will updating to NW5 SP6 have any impact?

Other ideas on how to close the open relay?
Truth-Compassion-Tolerance
 
I have clients in the same boat, except they are on MAPS blacklist. I don't know about the manual changes to the GWIA.CFG, but as to your other questions:
- server does NOT need to be restarted to take effect.
- NetWare support packs won't affect GWIA holes.
- We have moved several clients to Norton Internet mail gateway. It closes the relay holes, plus allows us to automatically delete EXE and other potentially harmful attachments and does a virus scan on all the others.

I haven't tried the GWIA patch, but planning to at one client within the week. Will repost with MAPS results after that.
 
Postscript: apparently one of the above steps actually resolved the problem. After some lapse in time, the ISP contacted us and told us that, as far as they were concerned, there is no longer a problem -- no more open relay.

Hope this is helpful to others...
Truth-Compassion-Tolerance
 
I had the same problem, but I got the open relay fixed.

One item I can share with you is that Novell has a new FGWIAC file (f) which was released 10/17/2001.

The other thing that you might try is to go into GWIA through NWADMIN, as you already had done and in the same place you indicated not to relay messages, check the option not to relay messages of 0kb or better.

You will find that GWIA will accept messages but will not relay them, they will be deposited in the <domain>gwia/wpgate/gwprob with an extension of .BAD

Hope this helps, and perhaps you can look at my problem as a result of upgrading to 5.5.4 which is also a current thread.

By the way did you install sp4 before using norouting. The Norouting switch will not work with previous versions of GW 5.5

Aloha
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top