Community Discussions and Support
Exempt an IP from strong auth. (solved)

[quote user="PaulW"]

[quote user="Jean-François Berne"]Is it possible to allow weak identification for some IPs ? I can't find this in the 'Connection Control' tab of MercuryS config.[/quote]

If it is a fixed IP address on your LAN, you can put it in Connection Control and allow it to relay (if that's what you want).  No authentication applies then - assuming you don't have the bottom box ticked (Only authenticated connections may relay), and you could turn it off in the camera.

How do your other workstations on the lan send mail - by authentication or IP address allowed?

[/quote]

Answers:

  • I HAD checked the box 'only authenticated SMTP connections may relay', which means that ...
  • ... others workstations on LAN (and on WAN) sent authentification;
  • camera had/has fixed IP

So I read again the help with your remarks in mind and actually solved the pb:

  • uncheked  'only authenticated may relay', but with...
  • ...strict local relaying
  • just the camera's IP in allowed connections list
  • kept weak auth. disabled

Now, all mail clients still must authenticate themselves with strong auth. - as they always did. Only the cam may relay without auth. at all, which is precisely what I needed.

Thank YOU !

 

JF 

[quote user="PaulW"]<p>[quote user="Jean-François Berne"]Is it possible to allow weak identification for some IPs ? I can't find this in the 'Connection Control' tab of MercuryS config.[/quote]</p> <p>If it is a fixed IP address on your LAN, you can put it in Connection Control and allow it to relay (if that's what you want).  No authentication applies then - assuming you don't have the bottom box ticked (Only authenticated connections may relay), and you could turn it off in the camera.</p> <p>How do your other workstations on the lan send mail - by authentication or IP address allowed?</p><p>[/quote]</p><p>Answers: </p><ul><li>I HAD checked the box 'only authenticated SMTP connections may relay', which means that ... </li><li>... others workstations on LAN (and on WAN) sent authentification; </li><li>camera had/has fixed IP</li></ul><p>So I read again the help with your remarks in mind and actually solved the pb:</p><ul><li>uncheked  'only authenticated may relay', but with... </li><li>...strict local relaying</li><li>just the camera's IP in allowed connections list</li><li>kept weak auth. disabled </li></ul><p>Now, all mail clients still must authenticate themselves with strong auth. - as they always did. Only the cam may relay without auth. at all, which is precisely what I needed. </p><p>Thank YOU !</p><p> </p><p>JF </p>

In a post with the subject "Order of Pegasus Mail‘s filtering tools (for incoming messages)" <http://community.pmail.com/forums/thread/1532.aspx> Thomas Nimmesgern writes about a "Global Whitelist"

He also writes about

    5. New Mail filtering rules
      5.1 on-open New Mail filtering rules
      5.2 on-close New Mail filtering rules 

 I can't find any reference in the manual to a  Global Whitelist or New Mail or "on-open" or "on-close"

 Can anyone please point me in the right direction.

 Many thanks.

&lt;p&gt;In a post with the subject &quot;Order of Pegasus Mail&lsquo;s filtering tools (for incoming messages)&quot; &amp;lt;http://community.pmail.com/forums/thread/1532.aspx&amp;gt; Thomas Nimmesgern writes about a &quot;Global Whitelist&quot; &lt;/p&gt;&lt;p&gt;He also writes about&lt;/p&gt;&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5. New Mail filtering rules &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5.1 on-open New Mail filtering rules &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5.2 on-close New Mail filtering rules&amp;nbsp; &lt;/p&gt;&lt;p&gt;&amp;nbsp;I can&#039;t find any reference in the manual to a&amp;nbsp; Global Whitelist or New Mail or &quot;on-open&quot; or &quot;on-close&quot;&lt;/p&gt;&lt;p&gt;&amp;nbsp;Can anyone please point me in the right direction.&lt;/p&gt;&lt;p&gt;&amp;nbsp;Many thanks. &lt;/p&gt;

Did you maybe look in the Mercury manual instead of the Pegasus manual?

/Rolf 

&lt;p&gt;Did you maybe look in the Mercury manual instead of the Pegasus manual?&lt;/p&gt;&lt;p&gt;/Rolf&nbsp;&lt;/p&gt;

Indeed :(  the reference to Pegasus was obvious but I missed it. (I do not use it)

On the other hand, surely the sequence referred to there must relate to Mercury as all the filtering is done by Mercury as far as I can see.

Quote:

In a nutshell, the order is:

  1. POP3-filtering rules
  2. Global Whitelist
  3. Spamhalter
  4. content control definitions and their lists
    4.1 the whitelist for a content control definition
    4.2 the blacklist for a content control definition
    4.3 the content control rules for a content control definition

 End Quote.

Surely SpamHalter and Content Control is controlled by Mercury so the Global Whitelist must also be there?

I am using SpamHalter and that has an Exclude list which to me looks like the equivalent of a global whilelist.  Is this maybe what is being referred to?

&lt;p&gt;Indeed :(&amp;nbsp; the reference to Pegasus was obvious but I missed it. (I do not use it) &lt;/p&gt;&lt;p&gt;On the other hand, surely the sequence referred to there must relate to Mercury as all the filtering is done by Mercury as far as I can see.&lt;/p&gt;&lt;p&gt;Quote:&lt;/p&gt;&lt;p&gt;In a nutshell, the order is: &lt;/p&gt;&lt;ol&gt;&lt;li&gt;POP3-filtering rules&lt;/li&gt;&lt;li&gt;Global Whitelist&lt;/li&gt;&lt;li&gt;Spamhalter&lt;/li&gt;&lt;li&gt;content control definitions and their lists &lt;span&gt; 4.1&lt;/span&gt; the whitelist for a content control definition &lt;span&gt;4.2&lt;/span&gt; the blacklist for a content control definition &lt;span&gt; 4.3&lt;/span&gt; the content control rules for a content control definition&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&amp;nbsp;End Quote.&lt;/p&gt;&lt;p&gt;Surely SpamHalter and Content Control is controlled by Mercury so the Global Whitelist must also be there?&lt;/p&gt;&lt;p&gt;I am using SpamHalter and that has an Exclude list which to me looks like the equivalent of a global whilelist.&amp;nbsp; Is this maybe what is being referred to? &lt;/p&gt;

Pegasus can be run integrated with Mercury or separately. Unless it says that a routine is based on Mercury the Pegasus manual describes how it works in Pegasus. Pegasus has a wide range of functionality that includes filtering, content control etc. SpamHalter can be run either with Mercury or in the client (or both).

/Rolf 

&lt;p&gt;Pegasus can be run integrated with Mercury or separately. Unless it says that a routine is based on Mercury the Pegasus manual describes how it works in Pegasus. Pegasus has a wide range of functionality that includes filtering, content control etc. SpamHalter can be run either with Mercury or in the client (or both).&lt;/p&gt;&lt;p&gt;/Rolf&amp;nbsp;&lt;/p&gt;

This may be a little out of date but it should give you a general overview of Mercury processing.

http://www.vandenbogaerde.net/pegasusmail/m_proorder.html

&lt;p&gt;This may be a little out of date but it should give you a general overview of Mercury processing.&lt;/p&gt;&lt;p&gt;http://www.vandenbogaerde.net/pegasusmail/m_proorder.html &lt;/p&gt;

[quote user="dilberts_left_nut"]

This may be a little out of date but it should give you a general overview of Mercury processing.

http://www.vandenbogaerde.net/pegasusmail/m_proorder.html

[/quote]

Old yet interesting: all these steps take place after MercuryS has placed the message in the queue.

I have a problem at MercuryS level:

  • MercuryS is SSL enabled, 'weak' identificators are disabled: this is for my off-LAN users.
  • I have an agent on the LAN which can only weak identification (an IP-camera)
  • Problem is: camera can't use MercuryS to send its journal, must use off-LAN SMTP server -> security issue

 Is it possible to allow weak identification for some IPs ? I can't find this in the 'Connection Control' tab of MercuryS config.

A sort of whitelist before the whitelist...

 Thanks,

JF

Mercury/32 version = 4.72

[quote user=&quot;dilberts_left_nut&quot;]&lt;p&gt;This may be a little out of date but it should give you a general overview of Mercury processing.&lt;/p&gt;&lt;p&gt;http://www.vandenbogaerde.net/pegasusmail/m_proorder.html &lt;/p&gt;&lt;p&gt;[/quote]&lt;/p&gt;&lt;p&gt;Old yet interesting: all these steps take place after MercuryS has placed the message in the queue. &lt;/p&gt;&lt;p&gt;I have a problem at MercuryS level: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;MercuryS is SSL enabled, &#039;weak&#039; identificators are disabled: this is for my off-LAN users. &lt;/li&gt;&lt;li&gt;I have an agent on the LAN which can only weak identification (an IP-camera)&lt;/li&gt;&lt;li&gt;Problem is: camera can&#039;t use MercuryS to send its journal, must use off-LAN SMTP server -&amp;gt; security issue &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&amp;nbsp;Is it possible to allow weak identification for some IPs ? I can&#039;t find this in the &#039;Connection Control&#039; tab of MercuryS config.&lt;/p&gt;&lt;p&gt;A sort of whitelist before the whitelist... &lt;/p&gt;&lt;p&gt;&amp;nbsp;Thanks,&lt;/p&gt;&lt;p&gt;JF&lt;/p&gt;&lt;p&gt;Mercury/32 version = 4.72 &lt;/p&gt;

[quote user="Jean-François Berne"]Is it possible to allow weak identification for some IPs ? I can't find this in the 'Connection Control' tab of MercuryS config.[/quote]

If it is a fixed IP address on your LAN, you can put it in Connection Control and allow it to relay (if that's what you want).  No authentication applies then - assuming you don't have the bottom box ticked (Only authenticated connections may relay), and you could turn it off in the camera.

How do your other workstations on the lan send mail - by authentication or IP address allowed?

&lt;P&gt;[quote user=&quot;Jean-Fran&ccedil;ois Berne&quot;]Is it possible to allow weak identification for some IPs ? I can&#039;t find this in the &#039;Connection Control&#039; tab of MercuryS config.[/quote]&lt;/P&gt; &lt;P&gt;If it is a fixed IP address on your LAN, you can put it in Connection Control and allow it to relay (if that&#039;s what you want).&amp;nbsp;&amp;nbsp;No&amp;nbsp;authentication&amp;nbsp;applies then - assuming you don&#039;t have the bottom box ticked (Only authenticated connections may relay), and you could turn it off in the camera.&lt;/P&gt; &lt;P&gt;How do your other workstations on the lan send mail - by authentication or IP address allowed?&lt;/P&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft