This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
networking:router:mikrotik_mail [2017/07/06 15:09] gcooper |
networking:router:mikrotik_mail [2018/05/25 09:35] (current) gcooper |
||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== Mikrotik Routers | + | ====== Mikrotik Routers |
+ | |||
+ | - **Define list of spam filter servers** | ||
+ | * Allowed to send mail to our internal mail server | ||
+ | - **Forward inbound SMTP traffic** to internal mail server | ||
+ | * But only from the spam filter servers | ||
+ | - **Block outbound SMTP traffic** | ||
+ | * But not from the internal mail server | ||
+ | |||
+ | <note tip> | ||
+ | |||
+ | ===== Example Configuration ===== | ||
+ | |||
+ | ^192.168.51.8 | ||
+ | ^ether1 | ||
+ | ^123.123.123.123 |External (Public) IP Address | ||
+ | |||
+ | FIXME You can use hostnames in newer versions of RouterOS. | ||
+ | |||
+ | :!: You must **adjust as necessary** (copy-> | ||
< | < | ||
Line 16: | Line 35: | ||
add address=208.70.91.0/ | add address=208.70.91.0/ | ||
+ | /ip firewall filter | ||
+ | add action=drop chain=forward comment=" | ||
+ | out-interface=ether1 protocol=tcp src-address=!192.168.51.8 | ||
+ | /ip firewall nat | ||
+ | add action=dst-nat chain=dstnat comment=" | ||
+ | dst-port=25 in-interface=ether1 protocol=tcp src-address-list=spamfilter to-addresses=192.168.51.8 | ||
</ | </ |