This forum uses cookies
This forum makes use of cookies to store your login information if you are registered, and your last visit if you are not. Cookies are small text documents stored on your computer; the cookies set by this forum can only be used on this website and pose no security risk. Cookies on this forum also track the specific topics you have read and when you last read them. Please confirm whether you accept or reject these cookies being set.

A cookie will be stored in your browser regardless of choice to prevent you being asked this question again. You will be able to change your cookie settings at any time using the link in the footer.

Pfsense and Sentora
#1
Pfsense and Sentora
Hi everyone,

I am considering building a new Sentora server. Over the past year my email server was taken over and has been used for spamming to the point Google, Yahoo, Outlook and several others have banned me. It got to the point where i just simply turned of postfix even after putting PFsense infront of Sentora.

It's impossible to continue without mail.

Does anyone have any tips or tutorial on installing sentora behind PFsense. I am using CentOS 7. How can I transfer from 1 server to the other? or should I redo everything manually? 

I have 1 wordpress/woocommerce website (still running). It has Wordfense running and I have blocked everything other than traffic from the U.S. but I would like to change this.

I am considering using hosting service as well that uses Sentora.

Not sure of what to do.
Reply
Thanks given by:
#2
RE: Pfsense and Sentora
When using pfsense what do you gain?

you can use already the firewall included in the server?

Mainly if you plan to expose only pfsense you will need to NAT and translate public ip to private ip and forward all traffic. I don't think it's advised then to use sentora DNS.

By default sentora will listen on port 80 on all ip's so no need for more changes.

You will need to forward 80 for http and 443 for https. If you need email you may need 25/110/143 ( als TLS ports if you setup any ).

M B
No support using PM (Auto adding to IGNORE list!), use the forum. 
How to ask
Freelance AWS Certified Architect & SysOps// DevOps

10$ free to start your VPS
Reply
Thanks given by:
#3
RE: Pfsense and Sentora
First off, if your server is sending out spam chances are it is one of your web sites being exploited. Also, there are a few very good tutorials in the Community Guides and HOW-TO forum on how to help lock down postfix and reduce spam.
-TGates - Project Council

SEARCH the Forums or read the DOCUMENTATION before posting!
Support Sentora and Donate: HERE

Find my support or modules useful? Donate to TGates HERE
Developers and code testers needed!
Contact TGates for more information
Reply
Thanks given by:
#4
RE: Pfsense and Sentora
If you are unable to locate the hacked website try to use clamav it can help.

M B
No support using PM (Auto adding to IGNORE list!), use the forum. 
How to ask
Freelance AWS Certified Architect & SysOps// DevOps

10$ free to start your VPS
Reply
Thanks given by:
#5
RE: Pfsense and Sentora
With sentora you can enable the blacklist check like: spamhaus or spamcop in your postfix service, so you can use your pfsense firewall to limit the concurrent connections on port 25 tcp for prevent spamming.

I recommend to enable PTR, SPF records into your DNS server.
Reply
Thanks given by:
#6
RE: Pfsense and Sentora
appreciate all the advice. I will give it go this weekend.

Pfsense give another layer of analyzing traffic before it hits the server. The server has multiple nics so I can forward the static IP to the server.

Pfsense should be able to analyze traffic going out as well. Still working on that.

I probably have an issue with SPF records.

our DNS zone has been loaded, but with errors. Some features may not work until corrected.

Please note that changes to your zone records can take up to 24 hours before they become 'live'.

Output of DNS zone checker: (main domain).
zone domain.net/IN: domain.net/MX 'mail.domain.net' has no address records (A or AAAA) zone domain.net/IN: 'domain.net' found type SPF record but no SPF TXT record found, add matching type TXT record zone domain.net/IN: loaded serial 2017110530 OK

v=spf1 ip4:xxx.xxx.xxx.xxx -all

spf for functioning domainB.
v=spf1 ip4:xxx.xxx.xxx.xxx a:mail.domainB.org -all


does anyone have any suggestions for a package that will analzye the outgoing traffic from sentora. (something I can install on Sentora)?
Reply
Thanks given by:


Possibly Related Threads…
Thread Author Replies Views Last Post
Is Sentora dead? rajeevrrs 2 2 ,992 12-17-2022, 09:20 AM
Last Post: TGates
Sentora debug and error files johnnyp 0 1 ,158 10-27-2022, 06:16 PM
Last Post: johnnyp
Transfer Account to another Sentora BenI 1 2 ,570 07-21-2022, 07:19 PM
Last Post: Nigel

Forum Jump:


Users browsing this thread: 1 Guest(s)