OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Tutorials and FAQs »
  • [Tutorial] OPNsense - Create a Postfix Mail Relay for Exchange Online in 8 steps
« previous next »
  • Print
Pages: [1]

Author Topic: [Tutorial] OPNsense - Create a Postfix Mail Relay for Exchange Online in 8 steps  (Read 5270 times)

vpx

  • Jr. Member
  • **
  • Posts: 87
  • Karma: 6
    • View Profile
[Tutorial] OPNsense - Create a Postfix Mail Relay for Exchange Online in 8 steps
« on: June 26, 2023, 04:25:48 pm »
1. Go to System->Settings->Plugins, search for "os-postfix" and install ith via the + sign on the right (in the screenshot it is already installed, that's why it shows a trash bin to remove it).



2. Refresh the Web GUI with F5 and you'll find "Postfix" under Services. Go to Services->Postfix->Domains and add your own domain, the field "Destination" is your Exchange Online target.



3. Go to senders and add your e-mail address which you want to send from, if you want to allow all e-mail addresses than just leave it empty.



4. Go to Services->Postfix->General and change "IP Version" to "IPv4" if you don't use IPv6. In "Trusted Networks" add your local subnet (in this case 192.168.3.0/24) or add single IPs for every allowed host. I don't know if the field "Smart Host" here is working at all, it had no effect if it was filled or empty. Maybe it just works with authentication which we don't need in this case.

« Last Edit: June 27, 2023, 07:35:54 am by vpx »
Logged

vpx

  • Jr. Member
  • **
  • Posts: 87
  • Karma: 6
    • View Profile
Re: [Tutorial] OPNsense - Create a Postfix Mail Relay for Exchange Online in 8 steps
« Reply #1 on: June 26, 2023, 04:28:27 pm »
5. Go to Firewall->Rules->LAN (or whatever Interface receives the mails in your configuration) and add the rule "Local Route Postfix". This is needed if you use a gateway (in this sample a Load Balancing/Failover-Multi WAN) as this gateway will just send out your mails directly into the Internet where it is discarded (because the destination is a class C address) instead of reaching the postfix service on your firewall. The rule is also needed if your rules are more restrictive than the "Default allow LAN to any rule".



6. Go to your Exchange Admin Center->Mail flow->Connectors and add a new connector named "Mailrelay" with the direction "Your organization's email server" to "Office 365".

« Last Edit: June 27, 2023, 07:37:42 am by vpx »
Logged

vpx

  • Jr. Member
  • **
  • Posts: 87
  • Karma: 6
    • View Profile
Re: [Tutorial] OPNsense - Create a Postfix Mail Relay for Exchange Online in 8 steps
« Reply #2 on: June 26, 2023, 04:29:14 pm »
7. Activate it and enter a description.



8. Choose authentication by IP address and enter the public static IP addresses from your ISP.

Logged

vpx

  • Jr. Member
  • **
  • Posts: 87
  • Karma: 6
    • View Profile
Re: [Tutorial] OPNsense - Create a Postfix Mail Relay for Exchange Online in 8 steps
« Reply #3 on: July 05, 2023, 03:23:25 pm »
Additional note:

You have to uncheck the option "Permit SASL Authenticated" in Services->Postfix->General as also described here:

https://serverfault.com/questions/1061757/opnsense-logs-every-second-postfix-smtpd-otp-unavailable-because-cant-read-wri

Otherwise you will get this message in the log with every mail:
Quote
2023-07-05T10:15:06   Error   postfix/smtpd   OTP unavailable because can't read/write key database /etc/opiekeys: Permission denied
Logged

tiermutter

  • Hero Member
  • *****
  • Posts: 1103
  • Karma: 61
    • View Profile
Re: [Tutorial] OPNsense - Create a Postfix Mail Relay for Exchange Online in 8 steps
« Reply #4 on: July 05, 2023, 04:07:41 pm »
Nice work. I never came to the idea setting up postfix on my Sense, instead I used a VM that also do some DDNS for multi WAN / failover I could'nt get to work on OPNsense fir the time being. When the time has come, I will maybe come back here again and discard the VM to save some ressources :)
Logged
i am not an expert... just trying to help...

mike0000

  • Newbie
  • *
  • Posts: 10
  • Karma: 0
    • View Profile
Re: [Tutorial] OPNsense - Create a Postfix Mail Relay for Exchange Online in 8 steps
« Reply #5 on: July 19, 2023, 06:41:22 pm »
Thank you for the tutorial. I use Exchange 365 and am wondering what the use cases for this are?
Logged

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6935
  • Karma: 584
    • View Profile
Re: [Tutorial] OPNsense - Create a Postfix Mail Relay for Exchange Online in 8 steps
« Reply #6 on: July 19, 2023, 06:43:40 pm »
Have an outbound mail server that can actually bounce instead of forward? Which Exchange cannot.
Have a local mail server for all your appliances, printers, scanners, UPS, ...
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Tutorials and FAQs »
  • [Tutorial] OPNsense - Create a Postfix Mail Relay for Exchange Online in 8 steps
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2