salut lol,
merci pour le lien je vais le lire ce tuto, entre temps voici ce que donnent les logs (/var/log/mail.log)
au moment de l’envoi d’un message de tatatoto@gmail.com
Mar 25 13:24:24 messagerie dovecot: imap-login: Login: user=<essai@mondomaine.org>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, TLS
Mar 25 13:24:24 messagerie dovecot: IMAP(essai@mondomaine.org): Disconnected: Logged out bytes=91/817
Mar 25 13:24:45 messagerie dovecot: imap-login: Login: user=<essai@mondomaine.org>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, TLS
Mar 25 13:24:46 messagerie dovecot: IMAP(essai@mondomaine.org): Disconnected: Logged out bytes=44/395
Mar 25 13:25:32 messagerie dovecot: imap-login: Login: user=<essai@mondomaine.org>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, TLS
Mar 25 13:25:32 messagerie postfix/smtpd[15111]: connect from localhost[127.0.0.1]
Mar 25 13:25:32 messagerie postfix/smtpd[15111]: C3B70E19B5: client=localhost[127.0.0.1]
Mar 25 13:25:32 messagerie postfix/cleanup[15114]: C3B70E19B5: message-id=<5fa6bc53df177400a8ad84d07c7c7e64@mondomaine.org>
Mar 25 13:25:32 messagerie postfix/qmgr[8119]: C3B70E19B5: from=<essai@mondomaine.org>, size=540, nrcpt=1 (queue active)
Mar 25 13:25:32 messagerie postfix/smtpd[15111]: disconnect from localhost[127.0.0.1]
Mar 25 13:25:32 messagerie dovecot: IMAP(essai@mondomaine.org): Disconnected: Logged out bytes=434/499
Mar 25 13:25:33 messagerie dovecot: imap-login: Login: user=<essai@mondomaine.org>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, TLS
Mar 25 13:25:33 messagerie dovecot: IMAP(essai@mondomaine.org): Disconnected: Logged out bytes=44/395
Mar 25 13:25:34 messagerie dovecot: imap-login: Login: user=<essai@mondomaine.org>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, TLS
Mar 25 13:25:34 messagerie dovecot: IMAP(essai@mondomaine.org): Disconnected: Logged out bytes=267/1608
Mar 25 13:25:34 messagerie dovecot: imap-login: Login: user=<essai@mondomaine.org>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, TLS
Mar 25 13:25:34 messagerie dovecot: IMAP(essai@mondomaine.org): Disconnected: Logged out bytes=119/530
Mar 25 13:25:35 messagerie postfix/smtpd[15128]: connect from localhost[127.0.0.1]
Mar 25 13:25:35 messagerie postfix/smtpd[15128]: 203AAE19B6: client=localhost[127.0.0.1]
Mar 25 13:25:35 messagerie postfix/cleanup[15114]: 203AAE19B6: message-id=<5fa6bc53df177400a8ad84d07c7c7e64@mondomaine.org>
Mar 25 13:25:35 messagerie postfix/smtpd[15128]: disconnect from localhost[127.0.0.1]
Mar 25 13:25:35 messagerie postfix/qmgr[8119]: 203AAE19B6: from=<essai@mondomaine.org>, size=1006, nrcpt=1 (queue active)
Mar 25 13:25:35 messagerie amavis[5843]: (05843-19) Passed CLEAN, LOCAL [127.0.0.1] [127.0.0.1] <essai@mondomaine.org> -> <tatatoto@gmail.com>, Message-ID: <5fa6bc53df177400a8ad84d07c7c7e64@mondomaine.org>, mail_id: nNWJgH91ca50, Hits: -1, size: 540, queued_as: 203AAE19B6, 2293 ms
Mar 25 13:25:35 messagerie postfix/smtp[15115]: C3B70E19B5: to=<tatatoto@gmail.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=2.4, delays=0.05/0.01/0/2.3, dsn=2.0.0, status=sent (250 2.0.0 Ok, id=05843-19, from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as 203AAE19B6)
Mar 25 13:25:35 messagerie postfix/qmgr[8119]: C3B70E19B5: removed
Mar 25 13:25:56 messagerie postfix/smtp[15129]: connect to gmail-smtp-in.l.google.com[173.194.70.27]:25: Connection timed out
Mar 25 13:26:17 messagerie postfix/smtp[15129]: connect to alt1.gmail-smtp-in.l.google.com[173.194.71.26]:25: Connection timed out
Mar 25 13:26:34 messagerie dovecot: imap-login: Login: user=<essai@mondomaine.org>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, TLS
Mar 25 13:26:34 messagerie dovecot: IMAP(essai@mondomaine.org): Disconnected: Logged out bytes=91/817
Mar 25 13:26:38 messagerie postfix/smtp[15129]: connect to alt2.gmail-smtp-in.l.google.com[173.194.79.26]:25: Connection timed out
Mar 25 13:26:59 messagerie postfix/smtp[15129]: connect to alt3.gmail-smtp-in.l.google.com[173.194.77.26]:25: Connection timed out
Mar 25 13:27:20 messagerie postfix/smtp[15129]: connect to alt4.gmail-smtp-in.l.google.com[209.85.225.26]:25: Connection timed out
Mar 25 13:27:20 messagerie postfix/smtp[15129]: 203AAE19B6: to=<tatatoto@gmail.com>, relay=none, delay=105, delays=0.01/0.01/105/0, dsn=4.4.1, status=deferred (connect to alt4.gmail-smtp-in.l.google.com[209.85.225.26]:25: Connection timed out)
Mar 25 13:27:34 messagerie dovecot: imap-login: Login: user=<essai@mondomaine.org>, method=PLAIN, rip=127.0.0.1, lip=127.0.0.1, TLS
Mar 25 13:27:34 messagerie dovecot: IMAP(essai@mondomaine.org): Disconnected: Logged out bytes=91/817
je vois que le statu est deferred, je ne sais pas ce que cela veut dire de toutes façons, rien n’a été envoyé.
voici ce que contient le fichier de zone (/etc/bind/mondomaine.org)de mon serveur dns:
;
; BIND data file for local loopback interface
;
$TTL 604800
@ IN SOA mondns.mondomaine.org. admin.mondomaine.org. (
2901201206
10800
3600
604800
38400 );
@ IN NS mondns.mondomaine.org.
@ IN MX 10 messagerie.mondomaine.org.
mondns.mondomaine.org. IN A adresse publique de mon serveur dns
www.mondomaine.org. IN A adresse publique de mon serveur web
messagerie.mondomaine.org. IN A adresse publique de mon serveur messagerie
mon firewall contient ceci:
#!/bin/sh
iptables -t nat -F
iptables -t filter -F
iptables -t nat -A POSTROUTING -o eth0 -s 172.16.0.0/16 -j MASQUERADE
echo 1 > /proc/sys/net/ipv4/ip_forward
########
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP
##############
#iptables -A INPUT -s 172.16.0.0/16 -j DROP
#iptables -A OUTPUT -s 172.16.0.0/16 -j DROP
#iptables -A FORWARD -s 172.16.0.0/16 -j DROP
#######
iptables -A INPUT -i lo -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
##############
######CONNEXIONS DEJA ETABLIES
iptables -A INPUT -i eth1 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -o eth1 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
########debloquer le ping
iptables -A INPUT -i eth1 -p icmp -j ACCEPT
iptables -A OUTPUT -o eth1 -p icmp -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -p icmp -j ACCEPT
iptables -A INPUT -i eth0 -p icmp -j ACCEPT
iptables -A OUTPUT -o eth0 -p icmp -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
#################
###debloquer dns
iptables -A INPUT -i eth1 -p udp --dport 53 -j ACCEPT
iptables -A INPUT -i eth1 -p tcp --dport 53 -j ACCEPT
iptables -A OUTPUT -o eth1 -p udp --dport 53 -j ACCEPT
iptables -A OUTPUT -o eth1 -p tcp --dport 53 -j ACCEPT
iptables -A INPUT -i eth0 -p udp --dport 53 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 53 -j ACCEPT
iptables -A OUTPUT -o eth0 -p udp --dport 53 -j ACCEPT
iptables -A OUTPUT -o eth0 -p udp --dport 53 -j ACCEPT
##############
###debloquer http
iptables -A OUTPUT -o eth0 -p tcp -m multiport --dports 80,443 -j ACCEPT
iptables -A FORWARD -p tcp -m multiport --dports 80,443 -j ACCEPT
iptables -A FORWARD -p tcp -m multiport --sports 80,443 -j ACCEPT
################
###debloquer port de connexion inscription nouveaux bacheliers####
#iptables -A OUTPUT -o eth0 -p tcp --dport 16001 -j ACCEPT
#iptables -A FORWARD -p tcp --dport 16001 -j ACCEPT
#iptables -A FORWARD -p tcp --sport 16001 -j ACCEPT
######################
###BLOQUER les scan xmas et null
iptables -A INPUT -p tcp --tcp-flags FIN,URG,PSH FIN,URG,PSH -j DROP
iptables -A INPUT -p tcp --tcp-flags ALL ALL -j DROP
iptables -A INPUT -p tcp --tcp-flags ALL NONE -j DROP
iptables -A INPUT -p tcp --tcp-flags SYN,RST SYN,RST -j DROP
######################
########BLOQUER LES CONNEXIONS NE COMMANCANT PAS PAR SYN
iptables -A INPUT -p tcp ! --syn -m state --state NEW -j DROP
###########bloquer les paquets avec fragments entrants
iptables -A INPUT -f -j DROP
##############bloquer les paquets broadcastés
##############bloquer les paquets broadcastés
iptables -A INPUT -m pkttype --pkt-type broadcast -j DROP
#########redirection vers le site
iptables -t nat -A PREROUTING -i eth0 -d @publiqueweb -p tcp --dport 80 -j DNAT --to-destination @publiqueweb
#######permettre le ftp
iptables -A OUTPUT -o eth0 -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --sport 21 -j ACCEPT
iptables -A OUTPUT -o eth1 -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -i eth1 -p tcp --sport 21 -j ACCEPT
#######permettre ssh
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -A OUTPUT -p tcp --dport 22 -j ACCEPT
#######permettre le serveur de temps
iptables -A OUTPUT -o eth0 -p udp --dport 123 -j ACCEPT
#######debloquer smtp
iptables -A OUTPUT -o eth0 -p tcp --dport 25 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --sport 25 -j ACCEPT
iptables -A OUTPUT -o eth1 -p tcp --dport 25 -j ACCEPT
iptables -A INPUT -i eth1 -p tcp --sport 25 -j ACCEPT
#######debloquer le port 4190 pour permettre le managesieve, plugin filtrage pour roundcube
iptables -A OUTPUT -o eth0 -p tcp --dport 4190 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --sport 4190 -j ACCEPT
iptables -A OUTPUT -o eth1 -p tcp --dport 4190 -j ACCEPT
iptables -A INPUT -i eth1 -p tcp --sport 4190 -j ACCEPT
######### bloquer tout le rest
iptables -A INPUT -p all -j DROP
iptables -A OUTPUT -p all -j DROP
iptables -A FORWARD -p all -j DROP
#############
je ne sais pas si j’ai une erreur dans le firewall
merci