22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

New for<br />

Domino 6<br />

statistics are maintained by the SMTP task, they are cumulative for the life of the<br />

task only and are lost when the task stops.<br />

You can view the statistics from the Domino Administrator or by using the SHOW<br />

STAT SMTP command from the server console. You can further expand the<br />

statistics to learn the number of times a given IP address is found on one of the<br />

configured DNSBLs. To collect the expanded information, you set the variable<br />

SMTPExpandDNSBLStats in the NOTES.INI file on the server. Because of the<br />

large numbers generated by the expanded set of statistics, Domino does not<br />

record the expanded statistics by default.<br />

Note: Domino uses IP version 4 (IPv4) addresses when querying DNS<br />

blacklist sites to find out if a connecting host is listed. If the connecting host<br />

has an IP version 6 (IPv6) address, Domino skips the DNSBL check for that<br />

host.<br />

Inbound relay enforcement<br />

When you first create a Configuration Settings document for a server, by default,<br />

the SMTP inbound relay controls, or anti-relay settings, apply to all external hosts<br />

only – that is, to hosts that are not located in the local Internet domain. After you<br />

set inbound relay controls, you can customize how Domino applies them by<br />

selecting inbound relay enforcement options to control to whom your relay<br />

restrictions apply.<br />

The available options allow you to specify how strictly to enforce the relay<br />

controls by letting you exempt certain hosts from enforcement. You can exempt<br />

hosts from relay enforcement based on:<br />

► Domain location - By default, Domino enforces relay controls for hosts<br />

outside the local Internet domain only. You can enforce stricter control by<br />

applying them to all connecting hosts or relax enforcement entirely so Domino<br />

does not perform any relay checks (not recommended).<br />

► Authentication status - By default, Domino applies relay controls to<br />

authenticated SMTP sessions. You can relax enforcement by exempting all<br />

authenticated users from relay checks.<br />

► Host name or IP address - By default, all external hosts are subject to relay<br />

controls. You can specify a list of hosts (by IP address or host name) to<br />

exempt from relay checks.<br />

Applying relay restrictions for internal hosts<br />

By default, Domino enforces anti-relay settings for external hosts only. Internal<br />

hosts are exempt from anti-relay checks so Domino does not consider an internal<br />

host as a possible relay, even if it's explicitly listed in the Inbound relay controls'<br />

Chapter 11. Domino/Notes 6 security features 519

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!