Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SMTP Header Rewriting

    Firewalling
    2
    5
    1.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      svensol
      last edited by

      Hi All,

      Coming from a watchguard background, I have been trying to find if there is a way of sanitising SMTP headers and removing internal network information.

      On the firebox configurations, it was/is known as an SMTP Proxy (or similar, I can't remember fully - it's been a couple of years) and you can search for specific entries within the headers and remove them on the fly.

      Is there anyway of doing this on pfSense?

      Thanks,

      Sven.

      1 Reply Last reply Reply Quote 0
      • F
        firewalluser
        last edited by

        Have you checked out mailscanner in the pfsense packages?
        Maybe this might do some or all of what you want to do?

        Capitalism, currently The World's best Entertainment Control System and YOU cant buy it! But you can buy this, or some of this or some of these

        Asch Conformity, mainly the blind leading the blind.

        1 Reply Last reply Reply Quote 0
        • S
          svensol
          last edited by

          It doesn't seem to do that, which is a shame.

          Thanks for pointing that one out though.

          Cheers,

          Sven.

          1 Reply Last reply Reply Quote 0
          • F
            firewalluser
            last edited by

            Some header info is essential, other header info is not, maybe you could look at the mail server itself to see if can output essential info only.

            For example MS Exchange server 2000/2003 did not used to put in the workstation ip address in the email header, but from 2007 onwards, it adds the workstation IP address to the email which is not essential info imo.

            Capitalism, currently The World's best Entertainment Control System and YOU cant buy it! But you can buy this, or some of this or some of these

            Asch Conformity, mainly the blind leading the blind.

            1 Reply Last reply Reply Quote 0
            • S
              svensol
              last edited by

              Yes, I've seen that too.  We have several mail servers around the perimeter, I was hoping that there could have been a way on the firewall but I'll have to see if there is a way of configuring exim4 or postfix to see if it's possible.

              Thanks anyway.

              Sven.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.