I can't figure out why my whitelist entry for 204.238.179.0/24 is being
ignored.  If not for a transient DNS failure this afternoon I'd not have
known this was broken.  The check_client_access whitelist entry _should_
have triggered before reject_unknown_client_hostname.  Any ideas why is
doesn't/didn't?

parent_domain_matches_subdomains =
        debug_peer_list smtpd_access_maps

smtpd_client_restrictions =
        check_recipient_access hash:/etc/postfix/access
        check_client_access hash:/etc/postfix/access
        ...
        ...
        reject_unknown_client_hostname
        reject_unauth_pipelining

smtpd_sender_restrictions =
        check_sender_access hash:/etc/postfix/access
        reject_non_fqdn_sender

smtpd_helo_required = yes
smtpd_helo_restrictions =
        check_recipient_access hash:/etc/postfix/access
        reject_non_fqdn_helo_hostname
        reject_invalid_helo_hostname
        reject_unknown_helo_hostname

smtpd_recipient_restrictions =
        permit_mynetworks
        reject_unauth_destination
        reject_unlisted_recipient
        check_recipient_access hash:/etc/postfix/access
        reject_rbl_client zen.spamhaus.org
        check_policy_service inet:127.0.0.1:60000

/etc/postfix/access
...
66.135.197                              OK
168.100.1                               OK
204.238.179                             OK
spam-l-boun...@spam-l.com               OK
owner-postfix-us...@cloud9.net          OK
majordomo-ow...@cloud9.net              OK
owner-postfix-us...@postfix.org         OK
...

Dec  4 13:39:15 greer postfix/smtpd[7124]: NOQUEUE: reject: RCPT from
unknown[204.238.179.8]: 450 4.7.1 <mx1.mfn.org>: Helo command rejected:
Host not found; from=<spam-l-boun...@spam-l.com>
to=<s...@hardwarefreak.com> proto=ESMTP helo=<mx1.mfn.org>

Any clues as to what's wrong?

--
Stan

Reply via email to