22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Internet<br />

132 Lotus Security Handbook<br />

number of relay hosts implemented varies by the size of the organization. Best<br />

practices involve having at least two independent SMTP relay hosts to provide<br />

redundancy. Often, organizations will designate one or more relay hosts as<br />

preferred “inbound” message relays, and one or more as designated “outbound”<br />

relays. The relay hosts can perform both inbound and outbound functions, both<br />

for redundancy as well as for some load balancing. For increased capacity, the<br />

number of relay hosts can be expanded horizontally. Figure 4-3 shows a typical<br />

SMTP relay host implementation that provides both inbound and outbound<br />

redundancy, and isolates the SMTP relays from the internal network.<br />

DNS<br />

(external)<br />

Administration Workstation<br />

Administration Network<br />

FTP server<br />

Figure 4-3 SMTP relay host implementation example<br />

External DNS entries:<br />

acme.com MX preference = 10, mail exchanger = smtp1.acme.com<br />

acme.com MX preference = 20, mail exchanger = smtp2.acme.com<br />

Firewall<br />

Firewall<br />

SMTP1 relay<br />

server<br />

Internal DNS entries (for outbound relay host):<br />

DNS<br />

(internal)<br />

Mail server<br />

Internal mail server network<br />

SMTP2 relay<br />

server<br />

relay.acme.com MX preference = 10, mail exchanger = smtp2.acme.com<br />

relay.acme.com MX preference = 20, mail exchanger = smtp1.acme.com<br />

Mail server<br />

In this example, the external DNS entries have two mail exchanger (MX) records,<br />

and they are weighted to favor smtp1 as the preferred choice to accept mail on

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!