Smarthost, Web server and Small Business Edition

Discuss the Scalix Server software

Moderators: ScalixSupport, admin

mweichert
Posts: 66
Joined: Fri Sep 22, 2006 9:32 am

Smarthost, Web server and Small Business Edition

Postby mweichert » Thu Sep 28, 2006 6:18 pm

At our company, we have a web server and postfix server in our DMZ.

We are purchasing Scalix Small Business Edition to install on a server in our internal network.

I know that Scalix Small Business Edition can only be installed on one server, so I just wanted to be sure that the SWA client could be installed on our web server in the DMZ and that all external e-mail could be sent to the postfix server.

Does anyone know the answer to this or have any experience with configuring something like this?

Thanks,
Mike
Last edited by mweichert on Fri Oct 13, 2006 2:44 pm, edited 1 time in total.

Valerion
Scalix Star
Scalix Star
Posts: 2730
Joined: Thu Feb 26, 2004 7:40 am
Location: Johannesburg, South Africa
Contact:

Re: Web server and Small Business Edition

Postby Valerion » Fri Sep 29, 2006 9:32 am

mweichert wrote:At our company, we have a web server and postfix server in our DMZ.

We are purchasing Scalix Small Business Edition to install on a server in our internal network.

I know that Scalix Small Business Edition can only be installed on one server, so I just wanted to be sure that the SWA client could be installed on our web server in the DMZ and that all external e-mail could be sent to the postfix server.


The Postfix server just needs to know to forward all mails to the real Scalix server. That's a standard mail relay setup which I know works, though I've only set it up with sendmail so far.

As to SWA, there's 2 ways.

1) You can install SWA and tomcat on the DMZ machine and point it to the HTTP, IMAP and LDAP ports of the internal server (/etc/opt/scalix has got all the config files for this). The SWA server software will run on your DMZ machine, so it will need to be powerful enough to cope with this.

2) You can install SWA and tomcat on your internal machine and apache on the DMZ machine. Transfer the Scalix apache configs regarding mod_jk to the DMZ machine, and have tomcat listen to 8009 on the wildcard interface, and you should be sorted. I have it running this way for my own LAN and it works well.

Just remember to open all the needed ports on your firewall to allow DMZ access to the Scalix server.

mweichert
Posts: 66
Joined: Fri Sep 22, 2006 9:32 am

Re: Web server and Small Business Edition

Postby mweichert » Fri Sep 29, 2006 10:23 am

Thank you very much for the reply!

I'm glad that it doesn't sounds like it will be a problem to setup. I just wanted to be sure that I could do this with the Small Business Edition of Scalix.

As for SWA, I think I'll go for option 2. I hope you don't mind me posting here again when we are ready to implement.

Thanks again,
Mike

Valerion wrote:
The Postfix server just needs to know to forward all mails to the real Scalix server. That's a standard mail relay setup which I know works, though I've only set it up with sendmail so far.

As to SWA, there's 2 ways.

1) You can install SWA and tomcat on the DMZ machine and point it to the HTTP, IMAP and LDAP ports of the internal server (/etc/opt/scalix has got all the config files for this). The SWA server software will run on your DMZ machine, so it will need to be powerful enough to cope with this.

2) You can install SWA and tomcat on your internal machine and apache on the DMZ machine. Transfer the Scalix apache configs regarding mod_jk to the DMZ machine, and have tomcat listen to 8009 on the wildcard interface, and you should be sorted. I have it running this way for my own LAN and it works well.

Just remember to open all the needed ports on your firewall to allow DMZ access to the Scalix server.

mweichert
Posts: 66
Joined: Fri Sep 22, 2006 9:32 am

Re: Smart host, Web server and Small Business Edition

Postby mweichert » Fri Oct 13, 2006 1:10 pm

Hi,

We are getting ready for implementation and I hope that you are able to help me again. :)

I'm setting up a Postfix server on the DMZ portion of our network. What I'm unsure of is how to configure the authentication of the Postfix server. SLES wants the backend of the Postfix server to be LDAP. I guess that would require me to create a separate LDAP server in the DMZ and populate it with user accounts that match the uid's of our internal LDAP server.

How do I "map" the authentication between the internal LDAP server used for Scalix and the external LDAP server used for the smart host?

OR...

Do I have the postfix server in the DMZ authenticate to the LDAP server in the LAN?

Finally, for the internal mail server (scalix) should I configure the domain name as mycompany.local and then for the postfix server in the DMZ using mycompany.com?

Thanks a bunch!
Mike



Valerion wrote:
mweichert wrote:At our company, we have a web server and postfix server in our DMZ.

We are purchasing Scalix Small Business Edition to install on a server in our internal network.

I know that Scalix Small Business Edition can only be installed on one server, so I just wanted to be sure that the SWA client could be installed on our web server in the DMZ and that all external e-mail could be sent to the postfix server.


The Postfix server just needs to know to forward all mails to the real Scalix server. That's a standard mail relay setup which I know works, though I've only set it up with sendmail so far.

As to SWA, there's 2 ways.

1) You can install SWA and tomcat on the DMZ machine and point it to the HTTP, IMAP and LDAP ports of the internal server (/etc/opt/scalix has got all the config files for this). The SWA server software will run on your DMZ machine, so it will need to be powerful enough to cope with this.

2) You can install SWA and tomcat on your internal machine and apache on the DMZ machine. Transfer the Scalix apache configs regarding mod_jk to the DMZ machine, and have tomcat listen to 8009 on the wildcard interface, and you should be sorted. I have it running this way for my own LAN and it works well.

Just remember to open all the needed ports on your firewall to allow DMZ access to the Scalix server.

florian
Scalix
Scalix
Posts: 3852
Joined: Fri Dec 24, 2004 8:16 am
Location: Frankfurt, Germany
Contact:

Postby florian » Sat Oct 14, 2006 1:35 pm

Why do you need authentication on your Postfix? The only scenario I could think of would be to allow external users (i.e. POP/IMAP clients) to submit email for delivery from the Internet - is that what you planned?

If so, Scalix provides an LDAP service and this would also allow postfix to be setup to authenticate against.

Cheers,
Florian.
Florian von Kurnatowski, Die Harder!

mweichert
Posts: 66
Joined: Fri Sep 22, 2006 9:32 am

Postby mweichert » Sun Oct 15, 2006 10:39 am

Sorry, I should of never wrote the post above when I did as I didn't really know how to describe what I was after. I've now done quite a bit of reading and research and set up postfix the way I needed to.

However, I do want IMAP clients to be able to send mail to the gateway and have it delivered to the internal scalix server. Do I have to setup something like Cyrus on the mail gateway to do that?

Thanks,
Mike

florian
Scalix
Scalix
Posts: 3852
Joined: Fri Dec 24, 2004 8:16 am
Location: Frankfurt, Germany
Contact:

Postby florian » Sun Oct 15, 2006 11:39 am

No you don't.

IMAP clients to not send eMail via IMAP - they use SMTP. So in this case, they would be talking to your Postfix. This, however, requires authentication to work.

Florian.
Florian von Kurnatowski, Die Harder!


Return to “Scalix Server”



Who is online

Users browsing this forum: No registered users and 2 guests

cron