Internet.com
Get your
ISP-News
courtesy of
internetnews.com




Search ISP-Lists
Search:
ISP Channel
CLEC-Planet
ISP Glossary
ISP News
ISP-Planet
ISP-Lists
E-mail Newsletters
Opt-in Announcements
Discussion Forums
internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

The ISP-Lists.com Email Discussion List Community

<- Previous Message | Next Message ->
Thread Index
[isp-dns] Re: Concerns about high Load

There's a quite highly used webmail interface on the mail storage server (Mirapoint). This uses the local smtpd to deliver.
well, that's web-app-to-SMTP-to-LDA, resolved from system or virtual accounts, fast and easy.

Although we have thought about setting the smarthost to be the gateway server. Also even though the external gateway will be doing most the work the smtpd on the storage server will still have to do local deliveries to mailboxes.
of course, but that's not over SMTP, that's over the Local Delivery Agent.

Look at IMGate.MEIway.com for your anti-abuse SMTP proxy. pre-configured,
proven, and free.
We have already got Mailscanner working with Sophos, spamassassin and RBL checking. But thanks for the tip I will have a look.
But I thought you wanted to migrate all that plumbing overhead from the mailbox server to the MX gateway? That's how to really free up and better protect your mailbox server.

Is it, do have a URL which shows statistics and benchmarks as a comparison between the 2.
no, but I've seen numbers in the bind user's list where bind8 was 30% to 40% faster that BIND9. ask on the bind list.

 Besides we are using views from Bind9.
As I said, I'm certain you aren't serving 1000's of queries/second, so BIND9 is fine.

Put BIND on the MX gateway as caching only NS.
We have 3 authoritative nameservers on our network which do most external query responses, this would only be a fall back for root server delegation. No machines have this box set as their resolver (apart from the gateway itself.)
an anti-abuse MX, at least as IMGate does it, is a voracious consumer of DNS, so having a c-o DNS on the MX gateway is advisable.

What a good guess =] That's exactly what it is using. 2x ATA100 40gb IBMs in a software mirrored RAID config.
well, find some pennies for a Promise TX2 or TX2000. If you're worried about throughput, softare RAID, any OS, is a good way to validate your worries.

Also in answer to the next question (see next thread) the gateway IS the firewall.
hmm, not very advisable. The firewall, for simplicity/security, ought to the firewall, routing, PAT/NATting, but not SMTP proxy, not DNS, not AV, not HTTP.

The mailstore is on a NAT'd private address range and this box port forwards the non-local services (e.g. pop3, imap, webmail, etc)...
and SMTP

So to round up this box will be... a MTA for 5000 users
the MX?

Virus scanning/Spam filtering for those 5000 users, Firewall/masq server for internal mailstore
... iow, the latter is the the mailbox server with SMTP, pop, and webmail services.

authoritative NS as well as resolver for demanding sendmail config.

Sorry about lack of clarity the first time around.
I'd go with

1. edge firewall with only public ip routing and packet filtering, not NAT/PAT.

2. behind which is a DMZ on a public subnet containing

a. the MX machine with anti-mail abuse stuff, and a c-o DNS. This DNS would also act as resolver for the private network. the DNS should allow-query only for the DMZ and outside ip of the inner firewall.

b. public web server

c. a delegated-only DNS, ie, no recursion.

3. inner firewall doing PAT/NAT, and packet filtering. the private net would contain

a. mailbox server, with port 25 access blocked by the outer firewall, and which relays all outbound the MX box in the DMZ.

b. perhaps a caching-only DNS to support the private net, and which forwards to the DNS in the DMZ. But the workstations could use the DMZ DNS as their nameserver.

The above "DNS forwarding architecture" avoids the complexity of split DNS, forward and reverse. And it certainly makes hardening the classic double-walled firewalling simpler because the inner and outer filtering boxes are running no apps or services beyond the minimum.

Len

Replies
[isp-dns] Re: Concerns about high Load, Spoof
Replies
[isp-dns] Re: Concerns about high Load, Len Conrad
[isp-dns] Re: Concerns about high Load, Spoof
<- Previous Message | Next Message ->
Thread Index

ISP Glossary
Find an ISP Term

Need Help?

JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
IBM eBook: Planning a Service Oriented Architecture
IBM eBook: Choosing the Right Architecture--What It Means for You and Your Business
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Avaya Article: Using Intelligent Presence to Create Smarter Business Applications
Intel Go Parallel Article: Getting Started with TBB on Windows
Microsoft Article: 7.0, Microsoft's Lucky Version?
Avaya Article: How to Feed Data into the Avaya Event Processor
IBM Article: Developing a Software Policy for Your Organization
Microsoft Article: Managing Virtual Machines with Microsoft System Center
Intel Go Parallel Article: Intel Threading Tools and OpenMP
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
HP Video: StorageWorks EVA4400 and Oracle
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
Silverlight 2 App and Walkthrough: Leverage Silverlight 2 with SQL Server and XML
IBM Article: Enterprise Search--Do You Know What's Out There?
HP Demo: StorageWorks EVA4400
Microsoft Article: The Progress and Promise of Deep Zoom
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES