All of lore.kernel.org
 help / color / mirror / Atom feed
* Using iptables with high volume mail
@ 2009-10-01 11:42 John Little
  2009-10-01 11:54 ` Richard Horton
  2009-10-01 16:03 ` Thomas Jacob
  0 siblings, 2 replies; 11+ messages in thread
From: John Little @ 2009-10-01 11:42 UTC (permalink / raw)
  To: netfilter

Hi all,

I work for a major email service provider.  Our
management has asked us to investigate using iptables as "NAT engine"
for outbound mail.

The outbound mail is the only traffic the
server will see.  No inbound mail, web, etc.  The machine(s) will have
a public facing NIC and a NIC for the internal LAN.

The machines will see over 1 million emails in a 24 hour period.

My questions are:
Can iptables handle this volume?

What modules, tables and rules to use to optimize iptables for this type volume?  All of the mail is sent on the standard port 25.  We need to optimize for quick deliverability.  (I've read the man page and looked at TOS with the mangle table.  I read somewhere that this only for udp.) 

Is there a way to estimate how much hardware we would need for a given volume of mail?

Are there any use cases that I can show management?

Is there commercial support available?

We really want to sell this to management.  We have gone through 2 major brands of commercial devices for NATting that aren't making the gradefor what we are paying.  Any ideas and insights appreciated.

Thanks,
John


      

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2009-10-02 19:04 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-10-01 11:42 Using iptables with high volume mail John Little
2009-10-01 11:54 ` Richard Horton
2009-10-01 12:45   ` John Little
2009-10-01 16:03 ` Thomas Jacob
2009-10-01 16:40   ` Gáspár Lajos
2009-10-01 19:39     ` John Little
2009-10-02 12:31       ` Thomas Jacob
2009-10-02 13:50         ` John Little
2009-10-02 14:52           ` Thomas Jacob
2009-10-02 15:08           ` Michele Petrazzo - Unipex
2009-10-02 19:04             ` John Little

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.