<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[iRedMail — iRedAdmin-Pro Support]]></title>
	<link rel="self" href="http://www.iredmail.org/forum/feed-atom-forum6.xml" />
	<updated>2013-05-21T12:13:04Z</updated>
	<generator>PunBB</generator>
	<id>http://www.iredmail.org/forum/</id>
		<entry>
			<title type="html"><![CDATA[Synchronizeing Problem - Outlook calendar / Contacts with Roundcube]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4890-synchronizeing-problem-outlook-calendar-contacts-with-roundcube-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: 0.8.3<br />- Store mail accounts in which backend (LDThrAP/MySQL/PGSQL): MySQL<br />- Linux/BSD distribution name and version: Ubuntu Linux 12.4<br />- Related log if you&#039;re reporting an issue:</p><p>Hi,</p><p>We have installed almost all Roundcube Plugins in our iRedmail Server. Now we are facing the issue regarding the Sync problem with Outlook and Roundcube. Calender and contacts are not Sync with Outlook and Roundcube and also with the iPhone.&nbsp; </p><p>Can give a suggestion or guide me to solve this issue?</p><p>Thanks</p>]]></summary>
			<author>
				<name><![CDATA[pravinbubby]]></name>
				<uri>http://www.iredmail.org/forum/user32394.html</uri>
			</author>
			<updated>2013-05-21T12:13:04Z</updated>
			<id>http://www.iredmail.org/forum/topic4890-synchronizeing-problem-outlook-calendar-contacts-with-roundcube-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Backup MX & Relay setting]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4876-backup-mx-relay-setting-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: 0.8.4<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP<br />- Linux/BSD distribution name and version: 5.8<br />- Related log if you&#039;re reporting an issue: <br />====<br />Hello Zhang<br />Can you show me step by step how to setting Backup MX &amp; Relay email<br />I could not found any documents of iRedAdmin relating this 2 features</p><p>Thanks for answers !</p>]]></summary>
			<author>
				<name><![CDATA[tge]]></name>
				<uri>http://www.iredmail.org/forum/user33092.html</uri>
			</author>
			<updated>2013-05-16T20:13:41Z</updated>
			<id>http://www.iredmail.org/forum/topic4876-backup-mx-relay-setting-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[New version is available!]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4872-new-version-is-available-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: 0.8.4<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP<br />- Linux/BSD distribution name and version: Centos6.3<br />- Related log if you&#039;re reporting an issue: <br />====</p><p>Apparently we have an upgrade available! <img src="http://www.iredmail.org/forum/img/smilies/big_smile.png" width="15" height="15" alt="big_smile" /></p><p>See screenshots.</p>]]></summary>
			<author>
				<name><![CDATA[orphans]]></name>
				<uri>http://www.iredmail.org/forum/user12022.html</uri>
			</author>
			<updated>2013-05-16T10:20:17Z</updated>
			<id>http://www.iredmail.org/forum/topic4872-new-version-is-available-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[About Disclaimer]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4867-about-disclaimer-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: <br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): <br />- Linux/BSD distribution name and version: <br />- Related log if you&#039;re reporting an issue: <br />==== <br />Hello Zhang<br />I have some questions about iRedMail-Pro Disclaimer<br />1. What&#039;s disclaimer? And it use for which case?<br />2. After active disclaimer, email sent have an attachment, file named winmail.dat, what is it and how i use it?</p><p>Thanks for answers</p>]]></summary>
			<author>
				<name><![CDATA[tge]]></name>
				<uri>http://www.iredmail.org/forum/user33092.html</uri>
			</author>
			<updated>2013-05-15T17:00:25Z</updated>
			<id>http://www.iredmail.org/forum/topic4867-about-disclaimer-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Admin Dashboard show No Domain and No Email Acconts]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4866-admin-dashboard-show-no-domain-and-no-email-acconts-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: 0.8.3<br />- Store mail accounts in which backend (LDThrAP/MySQL/PGSQL): MySQL<br />- Linux/BSD distribution name and version: Ubuntu Linux 12.4<br />- Related log if you&#039;re reporting an issue:<br />====</p><p>Hi Zhang,</p><p>When my client log in their admin site to create, delete or edit their domain users sometimes (not always) the admin dash board shows empty. The number of domain and number of users shows zero. But after sever times logout and login or if reset the admin account its shows the domain and users in the dashboard.</p><p>Feel strange and confused sometimes infront of our clients. Can you help me out to solve this issue permanently ?</p><p>thanks <br />Praveen</p>]]></summary>
			<author>
				<name><![CDATA[pravinbubby]]></name>
				<uri>http://www.iredmail.org/forum/user32394.html</uri>
			</author>
			<updated>2013-05-15T12:11:46Z</updated>
			<id>http://www.iredmail.org/forum/topic4866-admin-dashboard-show-no-domain-and-no-email-acconts-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[iRedAdmin Pro - adding a new address, wrong domain]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4863-iredadmin-pro-adding-a-new-address-wrong-domain-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: <br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): <br />- Linux/BSD distribution name and version: <br />- Related log if you&#039;re reporting an issue: <br />==== </p><p>I have an issue with iRedAdmin Pro where when I try to add an email address while under a specific domain, only the Primary/Default domain is listed.&nbsp; See image.&nbsp; So I am, in affect, not able to add an address.&nbsp; Have I missed something?</p><p>Thank you,</p>]]></summary>
			<author>
				<name><![CDATA[tonyd]]></name>
				<uri>http://www.iredmail.org/forum/user31948.html</uri>
			</author>
			<updated>2013-05-14T18:44:02Z</updated>
			<id>http://www.iredmail.org/forum/topic4863-iredadmin-pro-adding-a-new-address-wrong-domain-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[SSL for iRedAdmin-Pro]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4862-ssl-for-iredadminpro-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: 0.8.4<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP<br />- Linux/BSD distribution name and version: 5.9<br />- Related log if you&#039;re reporting an issue: <br />==== <br />Hello Zhang<br />I want to add Comodo Positive SSL cerfiticate for iRedAdmin-Pro<br />I have some questions:<br />1. How do i create CSR by tool generate_ssl_keys.sh ?<br />2. A SSL certificate have 3 files: .key, .pem &amp; .cert<br />How to add 3 files parameters to iRedMail apache and where the apche config file?<br />3. After added SSL for iRedAdmin-Pro, can i use SSL connection for DoveCot (IMAP &amp; POP), and SMTP (Postfix)?</p><p>Thanks for answers !</p>]]></summary>
			<author>
				<name><![CDATA[tge]]></name>
				<uri>http://www.iredmail.org/forum/user33092.html</uri>
			</author>
			<updated>2013-05-14T18:17:11Z</updated>
			<id>http://www.iredmail.org/forum/topic4862-ssl-for-iredadminpro-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Fail2Ban ignoreip Still Firewalling Whitelist]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4861-fail2ban-ignoreip-still-firewalling-whitelist-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: <br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): <br />- Linux/BSD distribution name and version: <br />- Related log if you&#039;re reporting an issue: <br />====</p><p>Hello,<br />I&#039;m having a problem with Fail2Ban adding drop rules to the iptables chain despite having specific IP&#039;s and IP Blocks listed on the ignoreips lines in the jail.conf, jail.local.&nbsp; I have even restarted iptables after stopping the fail2ban service.&nbsp; The whitelisted IP&#039;s still end up showing up as a DROP rule.&nbsp; Could someone please assist me with what I&#039;m missing?&nbsp; I have obfuscated the domains and first two octets for security.</p><p>Thank you,</p><div class="codebox"><pre><code>Chain INPUT (policy DROP)
num  target     prot opt source               destination         
1    DROP       all  --  er1.swift.*****.net  anywhere            
2    DROP       all  --  x.x.1.18  anywhere            
3    fail2ban-dovecot  tcp  --  anywhere             anywhere             multiport dports http,https,smtp,submission,pop3,pop3s,imap2,imaps,sieve
4    fail2ban-roundcube  tcp  --  anywhere             anywhere             multiport dports http,https,smtp,submission,pop3,pop3s,imap2,imaps,sieve
5    fail2ban-ssh  tcp  --  anywhere             anywhere             tcp dpt:ssh
6    ACCEPT     all  --  anywhere             anywhere             state RELATED,ESTABLISHED
7    ACCEPT     all  --  anywhere             anywhere            
8    ACCEPT     all  --  er1.swift.*****.net  anywhere            
9    ACCEPT     udp  --  10.0.0.25            anywhere             udp dpt:snmp
10   ACCEPT     udp  --  noc2.*****.net   anywhere             udp dpt:snmp
11   ACCEPT     udp  --  vpn.*****.net    anywhere             udp dpt:snmp
12   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:http
13   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:https
14   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:smtp
15   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:ssmtp
16   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:589 state NEW,ESTABLISHED
17   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:submission
18   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:pop3
19   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:pop3s
20   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:imap2
21   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:imaps
22   ACCEPT     tcp  --  vpn.*****.net    anywhere             tcp dpt:ssh
23   ACCEPT     icmp --  anywhere             anywhere             icmp echo-request
24   ACCEPT     tcp  --  vpn.*****.net    anywhere             tcp dpt:mysql
25   ACCEPT     tcp  --  vpn.*****.net    anywhere             tcp dpt:20133
26   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:http limit: avg 25/min burst 100

Chain FORWARD (policy DROP)
num  target     prot opt source               destination         
1    DROP       all  --  er1.swift.*****.net  anywhere            
2    DROP       all  --  x.x.2.18  anywhere            

Chain OUTPUT (policy ACCEPT)
num  target     prot opt source               destination         
1    ACCEPT     tcp  --  anywhere             anywhere             tcp spt:589 state ESTABLISHED

Chain fail2ban-dovecot (1 references)
num  target     prot opt source               destination         
1    RETURN     all  --  anywhere             anywhere            

Chain fail2ban-postfix (0 references)
num  target     prot opt source               destination         
1    RETURN     all  --  anywhere             anywhere            

Chain fail2ban-roundcube (1 references)
num  target     prot opt source               destination         
1    RETURN     all  --  anywhere             anywhere            

Chain fail2ban-ssh (1 references)
num  target     prot opt source               destination         
1    RETURN     all  --  anywhere             anywhere</code></pre></div><p># Fail2Ban not running<br /></p><div class="codebox"><pre><code>ps aux | grep fail2ban
root     17297  0.0  0.0   9384   924 pts/0    R+   09:27   0:00 grep --color=auto fail2ban</code></pre></div><p># iptables active fw rules<br /></p><div class="codebox"><pre><code>Chain INPUT (policy DROP)
num  target     prot opt source               destination         
1    DROP       all  --  x.x.1.18          anywhere            
2    ACCEPT     all  --  anywhere             anywhere             state RELATED,ESTABLISHED
3    ACCEPT     all  --  anywhere             anywhere            
4    ACCEPT     all  --  er1.swift.*****.net  anywhere            
5    ACCEPT     udp  --  10.0.0.25            anywhere             udp dpt:snmp
6    ACCEPT     udp  --  noc2.*****.net   anywhere             udp dpt:snmp
7    ACCEPT     udp  --  vpn.*****.net    anywhere             udp dpt:snmp
8    ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:http
9    ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:https
10   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:smtp
11   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:ssmtp
12   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:589 state NEW,ESTABLISHED
13   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:submission
14   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:pop3
15   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:pop3s
16   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:imap2
17   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:imaps
18   ACCEPT     tcp  --  vpn.*****.net    anywhere             tcp dpt:ssh
19   ACCEPT     icmp --  anywhere             anywhere             icmp echo-request
20   ACCEPT     tcp  --  vpn.*****.net    anywhere             tcp dpt:mysql
21   ACCEPT     tcp  --  vpn.*****.net    anywhere             tcp dpt:20133
22   ACCEPT     tcp  --  anywhere             anywhere             tcp dpt:http limit: avg 25/min burst 100

Chain FORWARD (policy DROP)
num  target     prot opt source               destination         
1    DROP       all  --  x.x.1.18  anywhere            

Chain OUTPUT (policy ACCEPT)
num  target     prot opt source               destination         
1    ACCEPT     tcp  --  anywhere             anywhere             tcp spt:589 state ESTABLISHED</code></pre></div><p># /etc/fail2ban/jail.conf<br /></p><div class="codebox"><pre><code># Fail2Ban configuration file.
#
# This file was composed for Debian systems from the original one
#  provided now under /usr/share/doc/fail2ban/examples/jail.conf
#  for additional examples.
#
# To avoid merges during upgrades DO NOT MODIFY THIS FILE
# and rather provide your changes in /etc/fail2ban/jail.local
#
# Author: Yaroslav O. Halchenko &lt;debian@onerussian.com&gt;
#
# $Revision$
#

# The DEFAULT allows a global definition of the options. They can be overridden
# in each jail afterwards.

[DEFAULT]

# &quot;ignoreip&quot; can be an IP address, a CIDR mask or a DNS host
ignoreip = 127.0.0.0/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 x.x.2.153 x.x.2.25 smtp663.redcondor.net smtp664.redcondor.net spam1.****.net x.x.25.0/24 x.x.26.0/24 x.x.27.0/24 x.x.28.0/24 12.44.144.0/24 x.x.1.30/32 cv.*****.com x.x.1.18 er1.swift.*****.net x.x.1.26 x.x.1.33 x.x.1.34 12.38.236.2
bantime  = 600
maxretry = 3

# &quot;backend&quot; specifies the backend used to get files modification. Available
# options are &quot;gamin&quot;, &quot;polling&quot; and &quot;auto&quot;.
# yoh: For some reason Debian shipped python-gamin didn&#039;t work as expected
#      This issue left ToDo, so polling is default backend for now
backend = auto

#
# Destination email address used solely for the interpolations in
# jail.{conf,local} configuration files.
destemail = noc@*****.net

#
# ACTIONS
#

# Default banning action (e.g. iptables, iptables-new,
# iptables-multiport, shorewall, etc) It is used to define
# action_* variables. Can be overridden globally or per
# section within jail.local file
banaction = iptables-multiport

# email action. Since 0.8.1 upstream fail2ban uses sendmail
# MTA for the mailing. Change mta configuration parameter to mail
# if you want to revert to conventional &#039;mail&#039;.
mta = sendmail

# Default protocol
protocol = tcp

# Specify chain where jumps would need to be added in iptables-* actions
chain = INPUT

#
# Action shortcuts. To be used to define action parameter

# The simplest action to take: ban only
action_ = %(banaction)s[name=%(__name__)s, port=&quot;%(port)s&quot;, protocol=&quot;%(protocol)s&quot;, chain=&quot;%(chain)s&quot;]

# ban &amp; send an e-mail with whois report to the destemail.
action_mw = %(banaction)s[name=%(__name__)s, port=&quot;%(port)s&quot;, protocol=&quot;%(protocol)s&quot;, chain=&quot;%(chain)s&quot;]
              %(mta)s-whois[name=%(__name__)s, dest=&quot;%(destemail)s&quot;, protocol=&quot;%(protocol)s&quot;, chain=&quot;%(chain)s&quot;]

# ban &amp; send an e-mail with whois report and relevant log lines
# to the destemail.
action_mwl = %(banaction)s[name=%(__name__)s, port=&quot;%(port)s&quot;, protocol=&quot;%(protocol)s&quot;, chain=&quot;%(chain)s&quot;]
               %(mta)s-whois-lines[name=%(__name__)s, dest=&quot;%(destemail)s&quot;, logpath=%(logpath)s, chain=&quot;%(chain)s&quot;]

# Choose default action.  To change, just override value of &#039;action&#039; with the
# interpolation to the chosen action shortcut (e.g.  action_mw, action_mwl, etc) in jail.local
# globally (section [DEFAULT]) or per specific section
action = %(action_)s

#
# JAILS
#

# Next jails corresponds to the standard configuration in Fail2ban 0.6 which
# was shipped in Debian. Enable any defined here jail by including
#
# [SECTION_NAME]
# enabled = true

#
# in /etc/fail2ban/jail.local.
#
# Optionally you may override any other parameter (e.g. banaction,
# action, port, logpath, etc) in that section within jail.local

[ssh]

enabled = false
port     = ssh
filter   = sshd
logpath  = /var/log/auth.log
maxretry = 6

[dropbear]

enabled = false
port     = ssh
filter   = sshd
logpath  = /var/log/dropbear
maxretry = 6

# Generic filter for pam. Has to be used with action which bans all ports
# such as iptables-allports, shorewall
[pam-generic]

enabled = false
# pam-generic filter can be customized to monitor specific subset of &#039;tty&#039;s
filter   = pam-generic
# port actually must be irrelevant but lets leave it all for some possible uses
port     = all
banaction = iptables-allports
port     = anyport
logpath  = /var/log/auth.log
maxretry = 6

[xinetd-fail]

enabled = false
filter    = xinetd-fail
port      = all
banaction = iptables-multiport-log
logpath   = /var/log/daemon.log
maxretry  = 2


[ssh-ddos]

enabled = false
port     = ssh
filter   = sshd-ddos
logpath  = /var/log/auth.log
maxretry = 6

#
# HTTP servers
#

[apache]

enabled = false
port     = http,https
filter   = apache-auth
logpath  = /var/log/apache*/*error.log
maxretry = 6

# default action is now multiport, so apache-multiport jail was left
# for compatibility with previous (&lt;0.7.6-2) releases
[apache-multiport]

enabled = false
port      = http,https
filter    = apache-auth
logpath   = /var/log/apache*/*error.log
maxretry  = 6

[apache-noscript]

enabled = false
port     = http,https
filter   = apache-noscript
logpath  = /var/log/apache*/*error.log
maxretry = 6

[apache-overflows]

enabled = false
port     = http,https
filter   = apache-overflows
logpath  = /var/log/apache*/*error.log
maxretry = 2

#
# FTP servers
#

[vsftpd]

enabled = false
port     = ftp,ftp-data,ftps,ftps-data
filter   = vsftpd
logpath  = /var/log/vsftpd.log
# or overwrite it in jails.local to be
# logpath = /var/log/auth.log
# if you want to rely on PAM failed login attempts
# vsftpd&#039;s failregex should match both of those formats
maxretry = 6


[proftpd]

enabled = false
port     = ftp,ftp-data,ftps,ftps-data
filter   = proftpd
logpath  = /var/log/proftpd/proftpd.log
maxretry = 6


[pure-ftpd]

enabled = false
port     = ftp,ftp-data,ftps,ftps-data
filter   = pure-ftpd
logpath  = /var/log/auth.log
maxretry = 6


[wuftpd]

enabled = false
port     = ftp,ftp-data,ftps,ftps-data
filter   = wuftpd
logpath  = /var/log/auth.log
maxretry = 6


#
# Mail servers
#

[postfix]

enabled = false
port     = smtp,ssmtp
filter   = postfix
logpath  = /var/log/mail.log


[couriersmtp]

enabled = false
port     = smtp,ssmtp
filter   = couriersmtp
logpath  = /var/log/mail.log

#
# Mail servers authenticators: might be used for smtp,ftp,imap servers, so
# all relevant ports get banned
#

[courierauth]

enabled = false
port     = smtp,ssmtp,imap2,imap3,imaps,pop3,pop3s
filter   = courierlogin
logpath  = /var/log/mail.log

[sasl]

enabled = false
port     = smtp,ssmtp,imap2,imap3,imaps,pop3,pop3s
filter   = sasl
# You might consider monitoring /var/log/mail.warn instead if you are
# running postfix since it would provide the same log lines at the
# &quot;warn&quot; level but overall at the smaller filesize.
logpath  = /var/log/mail.log

[dovecot]

enabled = false
port    = smtp,ssmtp,imap2,imap3,imaps,pop3,pop3s
filter  = dovecot
logpath = /var/log/mail.log

# DNS Servers


# These jails block attacks against named (bind9). By default, logging is off
# with bind9 installation. You will need something like this:
#
# logging {
#     channel security_file {
#         file &quot;/var/log/named/security.log&quot; versions 3 size 30m;
#         severity dynamic;
#         print-time yes;
#     };
#     category security {
#         security_file;
#     };
# };
#
# in your named.conf to provide proper logging

# !!! WARNING !!!
#   Since UDP is connection-less protocol, spoofing of IP and imitation
#   of illegal actions is way too simple.  Thus enabling of this filter
#   might provide an easy way for implementing a DoS against a chosen
#   victim. See
#    http://nion.modprobe.de/blog/archives/690-fail2ban-+-dns-fail.html
#   Please DO NOT USE this jail unless you know what you are doing.
#[named-refused-udp]
#
#enabled  = false
#port     = domain,953
#protocol = udp
#filter   = named-refused
#logpath  = /var/log/named/security.log

[named-refused-tcp]

enabled = false
port     = domain,953
protocol = tcp
filter   = named-refused
logpath  = /var/log/named/security.log</code></pre></div><p># /etc/fail2ban/jail.local<br /></p><div class="codebox"><pre><code>#
# File generated by iRedMail (2012.09.26.17.23.08):
#
# Version:  0.8.2
# Project:  http://www.iredmail.org/
#
# Community: http://www.iredmail.org/forum/
#


# Please refer to /etc/fail2ban/jail.conf for more examples.

[ssh-iredmail]
enabled     = true
filter      = sshd
action      = iptables[name=ssh, port=&quot;ssh&quot;, protocol=tcp]
               sendmail-whois[name=ssh, dest=tonyd@*****.net, sender=fail2ban@mail3.*****.net]
logpath     = /var/log/auth.log
maxretry    = 5
ignoreip    = 127.0.0.1 127.0.0.0/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16

[roundcube-iredmail]
enabled     = true
filter      = roundcube.iredmail
action      = iptables-multiport[name=roundcube, port=&quot;http,https,smtp,submission,pop3,pop3s,imap,imaps,sieve&quot;, protocol=tcp]
        sendmail-whois[name=roundcube, dest=tonyd@*****.net, sender=fail2ban@mail3.*****.net]
logpath     = /var/log/mail.log
findtime    = 3600
maxretry    = 5
bantime     = 3600
ignoreip = 127.0.0.0/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 x.x.2.153/32 x.x.2.25/32 x.x.25.0/24 x.x.26.0/24 x.x.27.0/24 x.x.28.0/24 12.44.144.0/24 x.x.1.30/32 cv.*****.com x.x.1.18/32 er1.swift.*****.net x.x.1.34/32 12.38.236.2/32

[dovecot-iredmail]
enabled     = true
filter      = dovecot.iredmail
action      = iptables-multiport[name=dovecot, port=&quot;http,https,smtp,submission,pop3,pop3s,imap,imaps,sieve&quot;, protocol=tcp]
        sendmail-whois[name=dovecot, dest=tonyd@*****.net, sender=fail2ban@mail3.*****.net]
logpath     = /var/log/dovecot.log
maxretry    = 5
findtime    = 300
bantime     = 3600
#ignoreip    = 127.0.0.1 127.0.0.0/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 x.x.2.153 x.x.2.25
ignoreip    = 127.0.0.1 127.0.0.0/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 x.x.2.153/32 x.x.2.25/32 smtp663.redcondor.net smtp664.redcondor.net spam1.*****.net x.x.25.0/24 x.x.26.0/24 x.x.27.0/24 x.x.28.0/24 12.44.144.0/24 x.x.1.30/32 cv.*****.com x.x.1.18/32 er1.swift.*****.net x.x.1.34/32 12.38.236.2/32

[postfix-iredmail]
enabled     = true
filter      = postfix.iredmail
action      = iptables-multiport[name=postfix, port=&quot;http,https,smtp,submission,pop3,pop3s,imap,imaps,sieve&quot;, protocol=tcp]
        sendmail-whois[name=postfix, dest=tonyd@*****.net, sender=fail2ban@mail3.*****.net]
#           sendmail[name=Postfix, dest=you@mail.com]
logpath     = /var/log/mail.log
bantime     = 3600
maxretry    = 5
ignoreip    = 127.0.0.1 127.0.0.0/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 x.x.2.153/32 x.x.2.25/32 smtp663.redcondor.net smtp664.redcondor.net spam1.*****.net x.x.25.0/24 x.x.26.0/24 x.x.27.0/24 x.x.28.0/24 12.44.144.0/24 x.x.1.30/32 cv.*****.com x.x.1.18/32 er1.swift.*****.net x.x.1.34/32 12.38.236.2/32</code></pre></div><p># IPTABLEs Default Rules<br /></p><div class="codebox"><pre><code>#
# Sample iptables rules. It should be localted at:
#   /etc/sysconfig/iptables
#
# Shipped within iRedMail project:
#   * http://iRedMail.googlecode.com/
#

*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]

# Keep state.
-A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

# Loop device.
-A INPUT -i lo -j ACCEPT

# Whitelist er1.swift.****.net
-A INPUT -s x.x.1.30 -j ACCEPT

# SNMP
-A INPUT -s 10.0.0.25 -p udp --dport 161 -j ACCEPT
-A INPUT -s x.x.3.11 -p udp --dport 161 -j ACCEPT
-A INPUT -s x.x.2.153 -p udp --dport 161 -j ACCEPT

# http, https
-A INPUT -p tcp --dport 80 -j ACCEPT
-A INPUT -p tcp --dport 443 -j ACCEPT

# smtp (25,465,589) Port forward 589 to 25
-A INPUT -p tcp --dport 25 -j ACCEPT
-A INPUT -p tcp --dport 465 -j ACCEPT
-A INPUT -i eth0 -p tcp --dport 589 -m state --state NEW,ESTABLISHED -j ACCEPT
-A OUTPUT -o eth0 -p tcp --sport 589 -m state --state ESTABLISHED -j ACCEPT
-A PREROUTING -t nat -p tcp --dport 589 -j REDIRECT --to-port 25

# ssmtp (587)
-A INPUT -p tcp --dport 587 -j ACCEPT

# pop3, pop3s
-A INPUT -p tcp --dport 110 -j ACCEPT
-A INPUT -p tcp --dport 995 -j ACCEPT

# imap, imaps
-A INPUT -p tcp --dport 143 -j ACCEPT
-A INPUT -p tcp --dport 993 -j ACCEPT

# ssh
-A INPUT -s x.x.2.153 -p tcp --dport 22 -j ACCEPT

# Allow PING from remote hosts.
-A INPUT -p icmp --icmp-type echo-request -j ACCEPT

# ejabberd
#-A INPUT -p tcp -m multiport --dport 5222,5223,5280 -j ACCEPT

# ldap/ldaps
#-A INPUT -p tcp -m multiport --dport 389,636 -j ACCEPT

# ftp.
#-A INPUT -p tcp -m multiport --dport 21,20 -j ACCEPT

# Allow connections from x.x.2.153 to MySQL and Plat Prov Listener
-A INPUT -s x.x.2.153 -p tcp -m tcp --dport 3306 -j ACCEPT
-A INPUT -s x.x.2.153 -p tcp -m tcp --dport 20133 -j ACCEPT

# DOS Protection
-A INPUT -p tcp --dport 80 -m limit --limit 25/minute --limit-burst 100 -j ACCEPT

COMMIT</code></pre></div>]]></summary>
			<author>
				<name><![CDATA[tonyd]]></name>
				<uri>http://www.iredmail.org/forum/user31948.html</uri>
			</author>
			<updated>2013-05-14T16:50:06Z</updated>
			<id>http://www.iredmail.org/forum/topic4861-fail2ban-ignoreip-still-firewalling-whitelist-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Deleted duplicate admin and now dont have global admin anymore]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4860-deleted-duplicate-admin-and-now-dont-have-global-admin-anymore-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: <br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): <br />- Linux/BSD distribution name and version: <br />- Related log if you&#039;re reporting an issue: <br />==== </p><p>version 0.8.4<br />MySQL<br />Ubuntu 12.04 LTS</p><p>I deleted an additional account labelled as a duplicate global admin in admins through UI.&nbsp; Now I dont have global admin anymore.&nbsp; How can I set the existing postmaster account to be global admin again.&nbsp; Currently its only marked as admin and doesnt see all domains and cannot set admin options.</p><p>Thanks<br />Robert</p>]]></summary>
			<author>
				<name><![CDATA[temabu]]></name>
				<uri>http://www.iredmail.org/forum/user18037.html</uri>
			</author>
			<updated>2013-05-14T00:07:44Z</updated>
			<id>http://www.iredmail.org/forum/topic4860-deleted-duplicate-admin-and-now-dont-have-global-admin-anymore-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Change iRedAdmin-Pro template]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4859-change-iredadminpro-template-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: 0.8.4<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP<br />- Linux/BSD distribution name and version: CentOS 5.8<br />- Related log if you&#039;re reporting an issue: <br />==== <br />Dear<br />I want to change iRedAdmin-Pro template, logo and copyright footer<br />How do i do?</p><p>Thanks for answers</p>]]></summary>
			<author>
				<name><![CDATA[tge]]></name>
				<uri>http://www.iredmail.org/forum/user33092.html</uri>
			</author>
			<updated>2013-05-13T11:22:04Z</updated>
			<id>http://www.iredmail.org/forum/topic4859-change-iredadminpro-template-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[forward to internal domain]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4848-forward-to-internal-domain-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version:&nbsp; 1.6.0<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL):&nbsp; iRedAdmin-Pro-MySQL<br />- Linux/BSD distribution name and version: openSUSE 12.2 (i586)<br />- Related log if you&#039;re reporting an issue: <br />==== <br />Hello,<br />I have a problem with email forwarding to other user in intranet domain. When I set some internet domain, everything is OK. When I set intranet domain (it does not exist in internet) after apply this addres is not in &quot;Forward mails to address&quot; field.<br />Old forward settings to intranet domain works fine and are visible<br />Thank you for your help<br />P.S. It became after upgrade, perhaps</p>]]></summary>
			<author>
				<name><![CDATA[HV]]></name>
				<uri>http://www.iredmail.org/forum/user30934.html</uri>
			</author>
			<updated>2013-05-10T08:29:49Z</updated>
			<id>http://www.iredmail.org/forum/topic4848-forward-to-internal-domain-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[|| iRedMail / iRedAdmin Reports ||]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4845-iredmail-iredadmin-reports-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: <br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): <br />- Linux/BSD distribution name and version: <br />- Related log if you&#039;re reporting an issue: <br />==== <br />We can only view the Reports i.e. sent &amp; received emails for a particular user and for a domain. At least add the facility to produce the reports to PDF file so that whenever required for investigation we can produce the same and the admin can generate these reports and give them to the management.</p><p>Thanks &amp; Regards,<br />Neil</p>]]></summary>
			<author>
				<name><![CDATA[indranil.kamulkar]]></name>
				<uri>http://www.iredmail.org/forum/user1422.html</uri>
			</author>
			<updated>2013-05-09T10:42:23Z</updated>
			<id>http://www.iredmail.org/forum/topic4845-iredmail-iredadmin-reports-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[whitelist/blacklist not working]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4844-whitelistblacklist-not-working-new-posts.html" />
			<summary type="html"><![CDATA[<p>Blacklisting/Whitelisting not working in iRedadmin Pro Ldap 1.8.1+Centos</p><p>I added domain name and email address in Blacklisting/Whitelisting Section using Control panel.but its not working..please advice</p>]]></summary>
			<author>
				<name><![CDATA[bijuedathodi]]></name>
				<uri>http://www.iredmail.org/forum/user31850.html</uri>
			</author>
			<updated>2013-05-09T09:34:54Z</updated>
			<id>http://www.iredmail.org/forum/topic4844-whitelistblacklist-not-working-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Not Relaying to SmartHost [SOLVED]]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4836-not-relaying-to-smarthost-solved-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: <br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): <br />- Linux/BSD distribution name and version: <br />- Related log if you&#039;re reporting an issue: <br />====</p><p>Hi,</p><p>I have enabled relaying for a domain in the iRedAdmin Panel.&nbsp; I have verified that it is set in the mailbox domains table.&nbsp; It is enabled.&nbsp; I have restarted postfix.&nbsp; It was working, now, it&#039;s not.&nbsp; I don&#039;t believe I&#039;ve broken the config.&nbsp; Yet, the mail does not relay through my defined transport.&nbsp; Anyone have an idea of why this would happen?</p><p>Thank you <img src="http://www.iredmail.org/forum/img/smilies/smile.png" width="15" height="15" alt="smile" /></p><br /><p>Second to last log entry showing relay.&nbsp; Should resemble the next example from a previous log the day before.<br /></p><div class="codebox"><pre><code>May  7 16:31:13 mail3 postfix/smtpd[30587]: connect from localhost[127.0.0.1]
May  7 16:31:13 mail3 postfix/smtpd[30587]: 432341006FC: client=localhost[127.0.0.1], sasl_method=LOGIN, sasl_username=tony@netald.com
May  7 16:31:13 mail3 postfix/cleanup[30593]: 432341006FC: message-id=&lt;51d40c5ae9c93ce392334c0e58e005b7@netald.com&gt;
May  7 16:31:14 mail3 postfix/qmgr[26553]: 432341006FC: from=&lt;tony@netald.com&gt;, size=20985, nrcpt=1 (queue active)
May  7 16:31:14 mail3 roundcube: User tony@netald.com [x.x.x.x]; Message for tonyd@gmail.com; 250: 2.0.0 Ok: queued as 432341006FC
May  7 16:31:14 mail3 postfix/smtpd[30587]: disconnect from localhost[127.0.0.1]
May  7 16:31:14 mail3 postfix/smtpd[30611]: connect from localhost[127.0.0.1]
May  7 16:31:14 mail3 postfix/smtpd[30611]: C8BC31008CD: client=localhost[127.0.0.1]
May  7 16:31:14 mail3 postfix/cleanup[30593]: C8BC31008CD: message-id=&lt;51d40c5ae9c93ce392334c0e58e005b7@netald.com&gt;
May  7 16:31:14 mail3 postfix/qmgr[26553]: C8BC31008CD: from=&lt;tony@netald.com&gt;, size=22081, nrcpt=1 (queue active)
May  7 16:31:14 mail3 postfix/smtpd[30611]: disconnect from localhost[127.0.0.1]
May  7 16:31:14 mail3 amavis[30574]: (30574-01) Passed CLEAN, MYNETS/MYUSERS LOCAL [127.0.0.1] [127.0.0.1] &lt;tony@netald.com&gt; -&gt; &lt;tonyd@gmail.com&gt;, Message-ID: &lt;51d40c5ae9c93ce392334c0e58e005b7@netald.com&gt;, mail_id: odHHG1y+ggZE, Hits: -9.986, size: 20985, queued_as: C8BC31008CD, 510 ms
May  7 16:31:14 mail3 postfix/smtp[30598]: 432341006FC: to=&lt;tonyd@gmail.com&gt;, relay=127.0.0.1[127.0.0.1]:10024, delay=1.6, delays=1.1/0/0/0.51, dsn=2.0.0, status=sent (250 2.0.0 from MTA([127.0.0.1]:10025): 250 2.0.0 Ok: queued as C8BC31008CD)
May  7 16:31:14 mail3 postfix/qmgr[26553]: 432341006FC: removed
May  7 16:31:17 mail3 postfix/smtp[30498]: C8BC31008CD: to=&lt;tonyd@gmail.com&gt;, relay=gmail-smtp-in.l.google.com[74.125.25.26]:25, delay=2.6, delays=0.01/0/0.15/2.4, dsn=2.0.0, status=sent (250 2.0.0 OK 1367969477 ql7si19664818pbc.26 - gsmtp)
May  7 16:31:17 mail3 postfix/qmgr[26553]: C8BC31008CD: removed</code></pre></div><br /><p>Correct Transport<br /></p><div class="codebox"><pre><code>May  7 13:57:58 mail3 postfix/smtp[27962]: 396A7100AFD: to=&lt;tony@netald.com&gt;, relay=mailgw.mydomain.net[x.x.x.x]:25, delay=0.02, delays=0/0/0/0.01, dsn=2.0.0, status=sent (250 OK)</code></pre></div><p><strong>MySQL Table mailbox/domains</strong><br />netald.com&nbsp; &nbsp; NetALD - Tony&#039;s Domain&nbsp; &nbsp; &nbsp; &nbsp; 0&nbsp; &nbsp; 0&nbsp; &nbsp; 0&nbsp; &nbsp; 0&nbsp; &nbsp; smtp:mailgw.mydomain.net:25&nbsp; &nbsp; 0&nbsp; &nbsp; 1024&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0&nbsp; &nbsp; 0&nbsp; &nbsp; 2013-04-13 23:40:30&nbsp; &nbsp; 2013-05-07 23:37:02&nbsp; &nbsp; 9999-12-31 00:00:00&nbsp; &nbsp; 1</p>]]></summary>
			<author>
				<name><![CDATA[tonyd]]></name>
				<uri>http://www.iredmail.org/forum/user31948.html</uri>
			</author>
			<updated>2013-05-07T23:58:49Z</updated>
			<id>http://www.iredmail.org/forum/topic4836-not-relaying-to-smarthost-solved-new-posts.html</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[iRedAdmin Pro - Integrated Amavisd, Greylist Policy, etc.]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/topic4832-iredadmin-pro-integrated-amavisd-greylist-policy-etc-new-posts.html" />
			<summary type="html"><![CDATA[<p>==== Required information ====<br />- iRedMail version: 1.6.0<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL<br />- Linux/BSD distribution name and version: Ubuntu 12.04.2<br />- Dell R310 Xeon Quad Core 2.40GHz x 2, 8GB<br />==== </p><p>Hi Zhang,</p><p>I have a question about the Admin Portal and it&#039;s integration of the various features of a mail system and that which is set up/enabled as part of the iRedAdmin package.&nbsp; Which I love BTW.&nbsp; In my case I installed with MySQL.&nbsp; So the amavisd and clubringer features were integrated to function with MySQL.&nbsp; Are there plans to integrate the management of these features into iRedAdmin so one can manage enabling/disabling, policy, greylisting white/blacklists, CheckHelo, etc?&nbsp; I found with a recent migration exercise that these were not available and managed via command line and direct access to the db tables.&nbsp; Very greatful for the responses and help, there were discrepancies in the assistance I received pointing me to policyd when postfix-cluebringer was the deployed method using the iRedAdmin package.&nbsp; Perhaps referring to their installation/experience.&nbsp; Again, very nice work!</p><p>tonyd</p>]]></summary>
			<author>
				<name><![CDATA[tonyd]]></name>
				<uri>http://www.iredmail.org/forum/user31948.html</uri>
			</author>
			<updated>2013-05-07T17:55:15Z</updated>
			<id>http://www.iredmail.org/forum/topic4832-iredadmin-pro-integrated-amavisd-greylist-policy-etc-new-posts.html</id>
		</entry>
</feed>
