Subject: Re: mail servers
To: None <tech-security@netbsd.org>
From: Martin Husemann <martin@duskware.de>
List: tech-security
Date: 03/04/2002 08:07:47
> (The same goes for async mounts on *BSD, and afaict, softupdates -- but
> neither of these is the default.)

No, not for softupdates (if they work correctly, which they are said to
do now at least in current).

Another point is: if I understood the original question correctly, this
mail server is not directly handling exterior incoming SMTP delivery, but
only local and outgoing mail. So no "rdr" rule on the NAT system would be
needed to make port 25 on the mail server visible to the outside world.
This can be done with carefull IPF rules - or by putting the mail server
on an inside machine.

Martin