Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #241528 > unrolled thread
| Started by | "Martin McCormick" <martin.m@suddenlink.net> |
|---|---|
| First post | 2021-10-20 18:50 +0200 |
| Last post | 2021-10-23 10:20 +0200 |
| Articles | 12 — 7 participants |
Back to article view | Back to linux.debian.user
eMail Com Between Hosts on a Private Net "Martin McCormick" <martin.m@suddenlink.net> - 2021-10-20 18:50 +0200
Re: eMail Com Between Hosts on a Private Net deloptes <emanoil.kotsev@deloptes.org> - 2021-10-20 19:20 +0200
Re: eMail Com Between Hosts on a Private Net Andrei POPESCU <andreimpopescu@gmail.com> - 2021-10-20 20:00 +0200
Re: eMail Com Between Hosts on a Private Net Charles Curley <charlescurley@charlescurley.com> - 2021-10-20 20:20 +0200
Re: eMail Com Between Hosts on a Private Net Joe <joe@jretrading.com> - 2021-10-20 20:20 +0200
Re: eMail Com Between Hosts on a Private Net "Martin McCormick" <martin.m@suddenlink.net> - 2021-10-21 03:30 +0200
Re: eMail Com Between Hosts on a Private Net Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-10-22 19:30 +0200
Re: eMail Com Between Hosts on a Private Net "Martin McCormick" <martin.m@suddenlink.net> - 2021-10-22 18:10 +0200
Re: eMail Com Between Hosts on a Private Net Joe <joe@jretrading.com> - 2021-10-22 19:10 +0200
Re: eMail Com Between Hosts on a Private Net Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-10-22 19:40 +0200
Re: eMail Com Between Hosts on a Private Net David Wright <deblis@lionunicorn.co.uk> - 2021-10-22 21:00 +0200
Re: eMail Com Between Hosts on a Private Net Andrei POPESCU <andreimpopescu@gmail.com> - 2021-10-23 10:20 +0200
| From | "Martin McCormick" <martin.m@suddenlink.net> |
|---|---|
| Date | 2021-10-20 18:50 +0200 |
| Subject | eMail Com Between Hosts on a Private Net |
| Message-ID | <DamWR-7rG-3@gated-at.bofh.it> |
The installation, here, is like millions of others. We are on a private VLAN with the router acting as the gateway to our ISP's network and the internet. There is nothing unusual about that so the question is Can systems on a 192.168.x VLAN use smtp to send mail to each other? I really should know the answer to this because I am a retired systems engineer who used unix systems and mailers all the time but that was in a university network and I would just assign a DNS name to each box and maybe a MX record if it was necessary so that box1.midlevel.edu could deliver mail to box2.midlevel.edu whether it was across the room or on another continent. The DNS support is what you don't have on a private VLAN so I want to do this in a safe but simple way. This would make it possible for Linux boxes on the network to send messages to the system I normally receive mail on so that squawks about a process crashing or some other problem are sure to be seen. The other systems sending those messages don't even necessarily need to send mail outside the network but they do need to send mail to the system I normally read mail on. I looked up this topic using duckduckgo and found very little hits that were on topic and lots of mercantile buzz about email hosting companies, etc. All are necessary but not what I was asking about. I have put static IP records in to the dhcp server on our router so 192.168.1.xx will always either have a specific host at that address or nothing if the MAC address changes and the record hasn't been updated. Also, I have put /etc/hosts files on Linux systems and a Mac and I believe there is a hosts file one can add to Windows systems for a similar effect. Thanks for any good ideas. Martin McCormick
[toc] | [next] | [standalone]
| From | deloptes <emanoil.kotsev@deloptes.org> |
|---|---|
| Date | 2021-10-20 19:20 +0200 |
| Message-ID | <DanpU-7R6-5@gated-at.bofh.it> |
| In reply to | #241528 |
Martin McCormick wrote: > The installation, here, is like millions of others. We are on a > private VLAN with the router acting as the gateway to our ISP's > network and the internet. There is nothing unusual about that so > the question is Can systems on a 192.168.x VLAN use smtp to send > mail to each other? > I think you are using the term VLAN improperly. FRom what I know VLAN is virtual LAN, which is usually achieved with tagging. But the answer to your question is yes they can. > I really should know the answer to this because I am a > retired systems engineer who used unix systems and mailers all > the time but that was in a university network and I would just > assign a DNS name to each box and maybe a MX record if it was > necessary so that box1.midlevel.edu could deliver mail to > box2.midlevel.edu whether it was across the room or on another > continent. > And for the 192.168.0.0/16 apply same rules ... well you can also use /etc/hosts. > The DNS support is what you don't have on a private VLAN > so I want to do this in a safe but simple way. > You do not have, because you did not install and configure, but from my experience if you manage more devices, you should consider using DHCP and MTA There are all sort of solutions like minimal DNS etc. IMO DHCP is must + DNS, minimal DNS or /etc/hosts file > This would make it possible for Linux boxes on the > network to send messages to the system I normally receive mail on > so that squawks about a process crashing or some other problem > are sure to be seen. > good conclusion - go for that > The other systems sending those messages don't even > necessarily need to send mail outside the network but they do > need to send mail to the system I normally read mail on. > I would consider something as server, because if your machine is not reachable, you will have the complains in the log files and bouncing mail. So basically you need the whole concept. IMAP or POP/MTA/DHCP/DNS > I looked up this topic using duckduckgo and found very > little hits that were on topic and lots of mercantile buzz about > email hosting companies, etc. All are necessary but not what I > was asking about. > > I have put static IP records in to the dhcp server on our > router so 192.168.1.xx will always either have a specific host at > that address or nothing if the MAC address changes and the record > hasn't been updated. > > Also, I have put /etc/hosts files on Linux systems and a > Mac and I believe there is a hosts file one can add to Windows > systems for a similar effect. if you implement DHCP and DNS in the router make sure you make backup of the configuration. you are left with the MTA and IMAP/POP -- FCD6 3719 0FFB F1BF 38EA 4727 5348 5F1F DCFE BCB0
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2021-10-20 20:00 +0200 |
| Message-ID | <Dao2B-842-3@gated-at.bofh.it> |
| In reply to | #241529 |
[Multipart message — attachments visible in raw view] — view raw
On Mi, 20 oct 21, 19:14:20, deloptes wrote: > Martin McCormick wrote: > > > The installation, here, is like millions of others. We are on a > > private VLAN with the router acting as the gateway to our ISP's > > network and the internet. There is nothing unusual about that so > > the question is Can systems on a 192.168.x VLAN use smtp to send > > mail to each other? > > > > I think you are using the term VLAN improperly. FRom what I know VLAN is > virtual LAN, which is usually achieved with tagging. Technically most routers are actually using VLANs to distinguish between WAN and LAN, but this is indeed irrelevant in this case. > But the answer to your question is yes they can. > > > I really should know the answer to this because I am a > > retired systems engineer who used unix systems and mailers all > > the time but that was in a university network and I would just > > assign a DNS name to each box and maybe a MX record if it was > > necessary so that box1.midlevel.edu could deliver mail to > > box2.midlevel.edu whether it was across the room or on another > > continent. > > > > And for the 192.168.0.0/16 apply same rules ... well you can also > use /etc/hosts. > > > The DNS support is what you don't have on a private VLAN > > so I want to do this in a safe but simple way. > > > > You do not have, because you did not install and configure, but from my > experience if you manage more devices, you should consider using DHCP and > MTA > > There are all sort of solutions like minimal DNS etc. IMO DHCP is must + > DNS, minimal DNS or /etc/hosts file In case you already own a public domain name you might be tempted to use that also internally. It's probably better to use a domain name that only exists on your LAN instead (e.g. use the domain name without the TLD), to avoid any issues in case a misconfigured system tries to send e-mail outside your LAN. > > This would make it possible for Linux boxes on the > > network to send messages to the system I normally receive mail on > > so that squawks about a process crashing or some other problem > > are sure to be seen. > > > > good conclusion - go for that > > > The other systems sending those messages don't even > > necessarily need to send mail outside the network but they do > > need to send mail to the system I normally read mail on. > > > > I would consider something as server, because if your machine is not > reachable, you will have the complains in the log files and bouncing mail. > > So basically you need the whole concept. IMAP or POP/MTA/DHCP/DNS Unless local mail is always read on the "server" system. > > I looked up this topic using duckduckgo and found very > > little hits that were on topic and lots of mercantile buzz about > > email hosting companies, etc. All are necessary but not what I > > was asking about. > > > > I have put static IP records in to the dhcp server on our > > router so 192.168.1.xx will always either have a specific host at > > that address or nothing if the MAC address changes and the record > > hasn't been updated. > > > > Also, I have put /etc/hosts files on Linux systems and a > > Mac and I believe there is a hosts file one can add to Windows > > systems for a similar effect. > > if you implement DHCP and DNS in the router make sure you make backup of the > configuration. you are left with the MTA and IMAP/POP In addition to all the above, you will need a minimal MTA on the machines only sending e-mail, e.g. something like nullmailer or esmtp. dma stands out here because it has a sort of queue and can also deliver locally if needed. For the "server" machine you will a real SMTP server. Typical choices are Exim (Debian's default) and Postfix (used by e.g. lists.debian.org), though they might be slightly difficult to configure. Another less known alternative is OpenSMTPD, which is lightweight enough to use also on the send-only systems. Hope this helps, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [next] | [standalone]
| From | Charles Curley <charlescurley@charlescurley.com> |
|---|---|
| Date | 2021-10-20 20:20 +0200 |
| Message-ID | <DaolY-8qR-3@gated-at.bofh.it> |
| In reply to | #241528 |
On Wed, 20 Oct 2021 11:46:11 -0500 "Martin McCormick" <martin.m@suddenlink.net> wrote: > Can systems on a 192.168.x VLAN use smtp to send > mail to each other? I know of no reason why not. However, one thing to be careful of: These are class C networks, so the default netmask will be 255.255.255.0. With that, you will need routing to go between networks, i.e. 192.168.100.y to 192.168.122.z. > Also, I have put /etc/hosts files on Linux systems and a > Mac and I believe there is a hosts file one can add to Windows > systems for a similar effect. There was the last time I worked with Windows, but that was a while ago. Is there any reason why you don't set up your own DNS server? One it is up and running, and DHCP is updating it as new computers come along, life is much easier. -- Does anybody read signatures any more? https://charlescurley.com https://charlescurley.com/blog/
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2021-10-20 20:20 +0200 |
| Message-ID | <DaolY-8qR-5@gated-at.bofh.it> |
| In reply to | #241528 |
On Wed, 20 Oct 2021 11:46:11 -0500 "Martin McCormick" <martin.m@suddenlink.net> wrote: > Also, I have put /etc/hosts files on Linux systems and a > Mac and I believe there is a hosts file one can add to Windows > systems for a similar effect. > > Indeed so, it is even in a folder called 'etc', which I think is in a 'drivers' folder. It's a while since I used it. There may be an existing default or example \etc\hosts file. The LMHosts file is also here, but of interest only to Windows networks for speeding up share lookups. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | "Martin McCormick" <martin.m@suddenlink.net> |
|---|---|
| Date | 2021-10-21 03:30 +0200 |
| Message-ID | <Dav45-3Vz-3@gated-at.bofh.it> |
| In reply to | #241532 |
Joe <joe@jretrading.com> writes: > Indeed so, it is even in a folder called 'etc', which I think is in a > 'drivers' folder. It's a while since I used it. There may be an > existing default or example \etc\hosts file. The LMHosts file is also > here, but of interest only to Windows networks for speeding up share > lookups. > > -- > Joe My thanks to all who replied and thanks for reminding me of some of the considerations one needs to think of when setting this all up since that's what I used to do as part of my job before retiring in 2015. As for there being 16 subnets in the 192.168.x.x number space, one can use variable-width subnet masks so unless you have a lot of hosts or, for some reason, are sharing space with another subnet, one can spread out to a Class B-style network which would be the whole space and have a subnet mask of 255.255.0.0 or you can make lots of little subnets of various mask sizes with blocks of 16 addresses being about the smallest subnet that is practical. Remember you always lose the all-zeros and all-ones broadcast addresses because they are special plus there is likely a router address taken by the router which leaves 13 addresses for hosts in each subnet. I remember early in the nineties our campus went from a single Class C to a Class B network and the whole campus used the Class B subnet mask with bridges holding the whole thing together. You should have seen some of the arp storms that would blow up like wild fire when somebody had a misconfigured host trying to be helpful or maybe deliberately misconfigured because somebody got their socks in a wad over something and started the fire on purpose. It wasn't long before we began more efficiently using the number space with big departments getting let's say 1024 or 512 possible addresses and others getting 16 or 32 addresses. By the time I left, we were using the huge private network space of 10.0.0.0 with aNAT or Network Address Translation to parts of the old Class B network and it generally worked well. I wrote a C then a perl program which would assign IP addresses for hosts on our networks that knew the sizes of all the subnet masks so assigning IP addresses was something anybody in our group could do without much more information other than what host name the customer wanted and what building it was in. My job was basically to encode all that in to rules for automation to keep us safe from making mistakes and it worked. Martin
[toc] | [prev] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2021-10-22 19:30 +0200 |
| Message-ID | <Db6wF-1Hb-7@gated-at.bofh.it> |
| In reply to | #241538 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Oct 20, 2021 at 8:21 PM Martin McCormick <martin.m@suddenlink.net> wrote: > .... > My thanks to all who replied and thanks for reminding me of some > of the considerations one needs to think of when setting this all > up since that's what I used to do as part of my job before > retiring in 2015. As for there being 16 subnets in the > 192.168.x.x number space, one can use variable-width subnet masks > .... > > I remember early in the nineties our campus went from a > single Class C to a Class B network and the whole campus used the > Class B subnet mask with bridges holding the whole thing > together. You should have seen some of the arp storms that would > .... > By the time I left, we were using the huge private > network space of 10.0.0.0 with aNAT or Network Address > Translation to parts of the old Class B network and it generally > worked well. > Yeah I did that transition a few times in a few organizations :-) > I wrote a C then a perl program which would assign IP > addresses for hosts on our networks that knew the sizes of all > the subnet masks so assigning IP addresses was something anybody > Recommending ipcalc to you. You can run it locally standalone or locally web-served, or invoke it remotely. Can pretty easily be embedded in your larger perl app. And naturally there are many perl modules available to you which do the same in many different ways, contexts, environments. > > Martin > >
[toc] | [prev] | [next] | [standalone]
| From | "Martin McCormick" <martin.m@suddenlink.net> |
|---|---|
| Date | 2021-10-22 18:10 +0200 |
| Message-ID | <Db5hf-127-3@gated-at.bofh.it> |
| In reply to | #241532 |
One more question I should know the answer to but am not sure of. The debian Buster system I use for email presently uses fetchmail to get mail from the ISP and is configured to use that ISP's smarthost for out-going mail. I do not want to effect (= muck this up) this functionality because it works well for now. Shouldn't I be able to install an imap server on the debian box and forward messages of interest to it, then reach imap4 on the private net from any system that speaks imap or has an imap client? That would do what I need to do. When I was researching, the article in wikipedia I read said that many commercial systems have email clients which understand imap, pop3, etc. The systems likely to do this on our network are a windows10 box, an iMac and maybe an iPad. The idea would be to forward an email message needing this attention to imap on the linux box, contact the Linux box from one of the devices I mentioned, and download the message at which point it would e as if that system had been hooked up to the ISP and received it. I was all ready to use .local as our domain name and then I looked that up and there is a good wikipedia article which explains how that is problematic and recommends using something like .lan, .office or something else that isn't likely to be registered as a top-level resolvable domain name. The machine I receive email on presently would be a good candidate for running a mdns but our netgear router advertises whatever dns's the isp uses for obvious reasons and that's fine but it would be nice if the mdns's address could also be known to clients on our network which could make DNS queries to each other's names that would resolve properly. Is there a way to advertise the mdns so that the router picks it up but doesn't drop the internet DNS's that we all need to resolve the rest of the world? I do remember when I was working, we explored open-source network authentication systems which involved fake DNS's that one had to advertise as such so their information wouldn't corrupt the proper working DNS's which could really mess things up if somebody happened to pickup and cache the wild card * that sent all new supplicants to the authentication server after they were already up and running. In our case, the corruption would be okay and done for good reasons but the dhcp server in our router already advertises two domain name servers so ours would have to be learned about by discovery. Thanks again. Martin McCormick
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2021-10-22 19:10 +0200 |
| Message-ID | <Db6dj-1AF-5@gated-at.bofh.it> |
| In reply to | #241604 |
On Fri, 22 Oct 2021 11:09:14 -0500 "Martin McCormick" <martin.m@suddenlink.net> wrote: > > Shouldn't I be able to install an imap server on the > debian box and forward messages of interest to it, then reach > imap4 on the private net from any system that speaks imap or has > an imap client? > Yes, certainly. An IMAP server can stand alone and act as an email repository or archive, accessed by many clients. It doesn't have to be plumbed into a live email system, it can just appear as an additional account in email clients which have separate real email accounts elsewhere. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2021-10-22 19:40 +0200 |
| Message-ID | <Db6Gl-1Kc-1@gated-at.bofh.it> |
| In reply to | #241604 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Oct 22, 2021 at 11:09 AM Martin McCormick <martin.m@suddenlink.net>
wrote:
> .....
> When I was researching, the article in wikipedia I read
> said that many commercial systems have email clients which
> understand imap, pop3, etc. The systems likely to do this on our
> network are a windows10 box, an iMac and maybe an iPad. The idea
>
>
Many corporate environments that are not committed to Microsoft
Exchange/Outlook take this approach.
Even when everyone in the corp uses a Microsoft client to read their mail,
it still may be served internally
with Pop/IMAP. Microsoft email software is not cheap. Of course many corps
use Google mail and it can be used privately, internally. Interactive
messaging and meeting is highly important today: Slack, Bluejeans, skype,
Microsoft Teams.....
Thanks again.
>
> Martin McCormick
>
>
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2021-10-22 21:00 +0200 |
| Message-ID | <Db7VM-2pm-9@gated-at.bofh.it> |
| In reply to | #241604 |
On Fri 22 Oct 2021 at 11:09:14 (-0500), Martin McCormick wrote: > I was all ready to use .local as our domain name and then > I looked that up and there is a good wikipedia article which > explains how that is problematic and recommends using something > like .lan, .office or something else that isn't likely to be > registered as a top-level resolvable domain name. The three strings that are the most certain never to be registered as TLDs are .corp, .home and .mail. https://features.icann.org/addressing-new-gtld-program-applications-corp-home-and-mail I use .corp merely because it's not a Common Word, and so grepping for it will hit the least number of false matches. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2021-10-23 10:20 +0200 |
| Message-ID | <DbkpX-1Qv-5@gated-at.bofh.it> |
| In reply to | #241604 |
[Multipart message — attachments visible in raw view] — view raw
On Vi, 22 oct 21, 11:09:14, Martin McCormick wrote: > One more question I should know the answer to but am not sure of. > The debian Buster system I use for email presently uses fetchmail > to get mail from the ISP and is configured to use that ISP's > smarthost for out-going mail. I do not want to effect > (= muck this up) this functionality because it works well for > now. Then don't touch it ;) > Shouldn't I be able to install an imap server on the > debian box and forward messages of interest to it, then reach > imap4 on the private net from any system that speaks imap or has > an imap client? Of course. It's probably easiest to have the IMAP server on the same system as the local SMTP server so there shouldn't be any "forwarding" involved. Just configure both to use the same storage location. In case of different programs accessing the same mail store the maildir format is recommended (over mbox), so that would be something like /home/<user>/Maildir. > That would do what I need to do. > > When I was researching, the article in wikipedia I read > said that many commercial systems have email clients which > understand imap, pop3, etc. The systems likely to do this on our > network are a windows10 box, an iMac and maybe an iPad. The idea > would be to forward an email message needing this attention to > imap on the linux box, contact the Linux box from one of the > devices I mentioned, and download the message at which point it > would e as if that system had been hooked up to the ISP and > received it. If you mean "download" as in use something like fetchmail than I would recommend against it. IMAP was designed to keep messages on the server, the client only has its local cache. With the IMAP server on the same LAN operations should be almost as fast as dealing with locally stored mails. For comparison, I'm reading this (and many other Debian lists) via IMAP to GMX with neomutt as IMAP client. Just the debian-user folder currently has more than 38000 messages. There are occasional pauses (a few seconds or so), particularly when changing folders, but I suspect this is due to the slow local storage (the entire OS runs from a USB stick). > I was all ready to use .local as our domain name and then > I looked that up and there is a good wikipedia article which > explains how that is problematic and recommends using something > like .lan, .office or something else that isn't likely to be > registered as a top-level resolvable domain name. > > The machine I receive email on presently would be a good > candidate for running a mdns but our netgear router advertises > whatever dns's the isp uses for obvious reasons and that's fine > but it would be nice if the mdns's address could also be known to clients > on our network which could make DNS queries to each other's names > that would resolve properly. If you are referring to mDNS here, that is actually meant to work without a server[1]. It's probably also much less flexible because it's meant to work with minimal or no configuration. A good candidate for a local DNS server would be your router, provided its firmware (more accurately operating system) supports this functionality. > Is there a way to advertise the mdns so that the router > picks it up but doesn't drop the internet DNS's that we all need > to resolve the rest of the world? What is the router supposed to do with your mDNS after it "picks it up"? > I do remember when I was working, we explored open-source > network authentication systems which involved fake DNS's that one > had to advertise as such so their information wouldn't corrupt > the proper working DNS's which could really mess things up if > somebody happened to pickup and cache the wild card * that sent > all new supplicants to the authentication server after they were > already up and running. > > In our case, the corruption would be okay and done for > good reasons but the dhcp server in our router already advertises two > domain name servers so ours would have to be learned about by > discovery. It shouldn't be necessary to pass the ISP's DNS servers to all local systems because most home routers can act as a caching DNS server (I would be really surprised if yours didn't), so they can advertise themselves as DNS server for your LAN via DHCP and forward queries to the ISP DNS servers (or other DNS servers of your choice) as needed. If this is somehow not possible (why?) you could either try to change the router's firmware (e.g. to something like OpenWrt) or use another system running 24/7 for DNS and DHCP (e.g. with something dnsmasq). It could very well be the same system running the SMTP (and IMAP) server. You would probably get better, specific suggestions if you would describe your network in more detail, in particular the router (model, firmware, configuration), and other systems that are providing (or planned to do so) services for your LAN. For client-only systems the operating system and general (intended) use, e.g. "want to read local mail from here" would be sufficient. [1] https://en.wikipedia.org/wiki/Multicast_DNS Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web