<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.tetrain.com/index.php?action=history&amp;feed=atom&amp;title=IIEST_final_report</id>
	<title>IIEST final report - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.tetrain.com/index.php?action=history&amp;feed=atom&amp;title=IIEST_final_report"/>
	<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=IIEST_final_report&amp;action=history"/>
	<updated>2026-07-27T11:09:34Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.9</generator>
	<entry>
		<id>https://wiki.tetrain.com/index.php?title=IIEST_final_report&amp;diff=4293&amp;oldid=prev</id>
		<title>Admin: Auto-created from uploaded PDF text extraction</title>
		<link rel="alternate" type="text/html" href="https://wiki.tetrain.com/index.php?title=IIEST_final_report&amp;diff=4293&amp;oldid=prev"/>
		<updated>2026-07-26T16:27:09Z</updated>

		<summary type="html">&lt;p&gt;Auto-created from uploaded PDF text extraction&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;Auto-generated from the uploaded PDF [[:File:IIEST_final_report.pdf|IIEST_final_report.pdf]]. This is an extracted-text rendering for searchability; see the original PDF for exact formatting, diagrams, tables, and images.&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
&amp;lt;nowiki&amp;gt;&lt;br /&gt;
Table Of Contents&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Table of Contents&lt;br /&gt;
OS Version in Old Live server was – CentOS 6.5 ..................................................................................... 2&lt;br /&gt;
&lt;br /&gt;
    1.1 Zimbra Version – 8.6.0_GA_1153.FOSS ....................................................................................... 3&lt;br /&gt;
&lt;br /&gt;
    1.2 Total No of Servers – 1 ................................................................................................................. 3&lt;br /&gt;
&lt;br /&gt;
    1.3 Total No of Accounts – 3632 ........................................................................................................ 4&lt;br /&gt;
&lt;br /&gt;
    1.4 No of domains – 71 ..................................................................................................................... 4&lt;br /&gt;
&lt;br /&gt;
    1.5 SSL – Expires on Oct 29, 2023. By Sectigo Limited....................................................................... 5&lt;br /&gt;
&lt;br /&gt;
    1.6 Data – 2.3 TB ................................................................................................................................ 6&lt;br /&gt;
&lt;br /&gt;
Installation of OS RHEL 8.7:..................................................................................................................... 7&lt;br /&gt;
&lt;br /&gt;
Installation &amp;amp; Configuration of Zimbra ................................................................................................. 12&lt;br /&gt;
&lt;br /&gt;
    1.1 Prerequisites :- ........................................................................................................................... 12&lt;br /&gt;
&lt;br /&gt;
    1.2 DNS Configuration: .................................................................................................................... 12&lt;br /&gt;
&lt;br /&gt;
    1.3 Other Host Configurations ......................................................................................................... 15&lt;br /&gt;
&lt;br /&gt;
Zimbra Installation ................................................................................................................................ 16&lt;br /&gt;
&lt;br /&gt;
    3.1 Log onto the Administration Console ........................................................................................ 29&lt;br /&gt;
&lt;br /&gt;
Zimbra Migration .................................................................................................................................. 30&lt;br /&gt;
&lt;br /&gt;
Installing DRBD on both the nodes : ..................................................................................................... 35&lt;br /&gt;
&lt;br /&gt;
Configuration of Spam Filtering ............................................................................................................ 40&lt;br /&gt;
&lt;br /&gt;
    1.1 Outright Blocking With Postfix DNS Protocol Checks ................................................................ 40&lt;br /&gt;
&lt;br /&gt;
    1.2 Outright Blocking of Bad Sending Servers ................................................................................. 40&lt;br /&gt;
&lt;br /&gt;
    1.3 Outright Blocking of Certain Attachments ................................................................................. 40&lt;br /&gt;
&lt;br /&gt;
    1.4 Enforcing a match between FROM address and sasl username................................................ 42&lt;br /&gt;
&lt;br /&gt;
    1.5 Tuning SpamTag and SpamKill ................................................................................................... 43&lt;br /&gt;
&lt;br /&gt;
    1.6 Cbpolicy webui activated, and it’s authentication implemented. ............................................. 44&lt;br /&gt;
&lt;br /&gt;
OS Version in Old Live server was – CentOS 6.5&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  1.1   Zimbra Version – 8.6.0_GA_1153.FOSS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  1.2   Total No of Servers – 1&lt;br /&gt;
&lt;br /&gt;
1.3   Total No of Accounts – 3632&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
1.4   No of domains – 71&lt;br /&gt;
&lt;br /&gt;
1.5     SSL – Expires on Oct 29, 2023. By Sectigo&lt;br /&gt;
   Limited.&lt;br /&gt;
&lt;br /&gt;
1.6   Data – 2.3 TB&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Installation of OS RHEL 8.7:&lt;br /&gt;
2.1. Download the RHEL 8.7 ISO image.&lt;br /&gt;
&lt;br /&gt;
2.2. Make a bootable pen drive with the ISO image.&lt;br /&gt;
&lt;br /&gt;
2.3. Insert the pen drive &amp;amp; boot the server.&lt;br /&gt;
&lt;br /&gt;
2.4. Press F11 for Boot Menu&lt;br /&gt;
&lt;br /&gt;
2.5. Select the USB drive and start Installation.&lt;br /&gt;
&lt;br /&gt;
2.6. Partitioning done –&lt;br /&gt;
&lt;br /&gt;
/opt – 6200G&lt;br /&gt;
&lt;br /&gt;
/ - 420G&lt;br /&gt;
&lt;br /&gt;
Swap – 64G&lt;br /&gt;
&lt;br /&gt;
/boot – 1G&lt;br /&gt;
&lt;br /&gt;
2.7. Select Timezone, language, set root and admin account passswords. Login to RedHat&lt;br /&gt;
account and attach subscription via the subscription manager. Begin installation.&lt;br /&gt;
&lt;br /&gt;
2.8. Complete the installation and reboot.&lt;br /&gt;
&lt;br /&gt;
Installation &amp;amp; Configuration of Zimbra&lt;br /&gt;
&lt;br /&gt;
    1.1         Prerequisites :-&lt;br /&gt;
    •   Install the following packages - Perl perl-core nmap libidn gmp libaio libstdc++ unzip sysstat&lt;br /&gt;
        wget .&lt;br /&gt;
&lt;br /&gt;
    •   # yum install perl perl-core nmap libidn gmp libaio libstdc++ unzip sysstat wget&lt;br /&gt;
&lt;br /&gt;
    1.2         DNS Configuration:&lt;br /&gt;
        When you create a domain during the installation process, ZCS checks to see if you have an&lt;br /&gt;
MX record correctly configured. If it is not, an error is displayed suggesting that the domain name have&lt;br /&gt;
an MX record configured in DNS.&lt;br /&gt;
&lt;br /&gt;
    •   Install dns (bind) packages by below command:&lt;br /&gt;
          # yum install bind bind-chroot bind-utils&lt;br /&gt;
&lt;br /&gt;
    •   Enable named service on system boot time by below command:&lt;br /&gt;
          # systemctl enable named&lt;br /&gt;
&lt;br /&gt;
    •   Make the entry of your IP in /etc/named.conf file in the listen-on port line. Also add the IP&lt;br /&gt;
        address in the allow query line.&lt;br /&gt;
&lt;br /&gt;
•   Create zone file location configuration for domains.&lt;br /&gt;
&lt;br /&gt;
•   Create forward zone file -&lt;br /&gt;
    [root@node1 ]# vi /var/named/node1.iiests.ac.in.hosts&lt;br /&gt;
&lt;br /&gt;
1.3         Other Host Configurations&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
•   Enter the Zimbra hostname and IP address in /etc/hosts file. Also enter the external ldap&lt;br /&gt;
    details in the file.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
•   Disable postfix - # systemctl disable postfix&lt;br /&gt;
&lt;br /&gt;
•   Make the Selinux permanently disabled –&lt;br /&gt;
    [root@node1 ~]# vi /etc/selinux/config&lt;br /&gt;
&lt;br /&gt;
Zimbra Installation&lt;br /&gt;
  •   Change directory to /opt - # cd /opt&lt;br /&gt;
  •   Download Zimbra 8.8.15&lt;br /&gt;
      #                    wget             https://files.zimbra.com/downloads/8.8.15_GA/zcs-&lt;br /&gt;
      8.8.15_GA_3953.RHEL8_64.20200629025823.tgz&lt;br /&gt;
  •   Unzip the file –&lt;br /&gt;
      # tar -xvzf zcs-8.8.15_GA_3953.RHEL8_64.20200629025823.tgz&lt;br /&gt;
&lt;br /&gt;
•   Change directory to zcs-8.8.15&lt;br /&gt;
    # cd zcs-8.8.15_GA_3953.RHEL8_64.20200629025823&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
•   Execute the installation script –&lt;br /&gt;
    # ./install.sh&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Press 4 to set admin password&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Installing Zimlets&lt;br /&gt;
&lt;br /&gt;
Installation completed.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
    3.1 Log onto the Administration Console&lt;br /&gt;
Open any of your favorite web browser and access the zimbra web administration console with your&lt;br /&gt;
10.1.0.77 or hostname and supply the credentials.&lt;br /&gt;
&lt;br /&gt;
https://mail.iiests.ac.in:7071&lt;br /&gt;
&lt;br /&gt;
https://10.1.0.77:7071&lt;br /&gt;
&lt;br /&gt;
Zimbra Migration&lt;br /&gt;
4.1 Make sure that the hostname, admin user and password, ldap password and mysql password are&lt;br /&gt;
set same as the old server.&lt;br /&gt;
4.2 Preparing the Old Server –&lt;br /&gt;
    1. Create an LDAP dump directory. As root, type&lt;br /&gt;
&lt;br /&gt;
        a. mkdir /backup&lt;br /&gt;
        b. chown zimbra:zimbra /backup&lt;br /&gt;
&lt;br /&gt;
    2. Backup the LDAP data, as zimbra, type&lt;br /&gt;
         /opt/zimbra/libexec/zmslapcat /backup&lt;br /&gt;
&lt;br /&gt;
   3. Export MySQL data. Before you start, make sure that /backup is large enough to hold all the&lt;br /&gt;
data. Depending on the original database size, this can be very large. If you have large configuration,&lt;br /&gt;
you may want to run this command with nohup so that the session does not terminate. Type&lt;br /&gt;
&lt;br /&gt;
/opt/zimbra/common/bin/mysqldump -f -S /opt/zimbra/data/tmp/mysql/mysql.sock \&lt;br /&gt;
&lt;br /&gt;
-u zimbra --password=`zmlocalconfig -s -m nokey \&lt;br /&gt;
&lt;br /&gt;
zimbra_mysql_password` --all-databases --single-transaction \&lt;br /&gt;
&lt;br /&gt;
&amp;gt; /backup/mysql.sql&lt;br /&gt;
&lt;br /&gt;
4.3 Preparing the New Server&lt;br /&gt;
&lt;br /&gt;
    1. LDAP data import on new server –&lt;br /&gt;
&lt;br /&gt;
As Zimbra&lt;br /&gt;
  Stop ldap – $ ldap stop&lt;br /&gt;
Cleanup the old database and move it to a new location&lt;br /&gt;
$ cd /opt/Zimbra/data/ldap&lt;br /&gt;
$ mv mdb mdb.old&lt;br /&gt;
&lt;br /&gt;
Create the new directory structure –&lt;br /&gt;
$ mkdir -p mdb/db&lt;br /&gt;
&lt;br /&gt;
Import the data –&lt;br /&gt;
$ /opt/Zimbra/libexec/zmslapadd /backup/ldap.bak&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
    2. Mysql import –&lt;br /&gt;
       $ mysql.server start [start mysql]&lt;br /&gt;
       $ mysql -f zimbra &amp;lt; /backup/mysql.sql&lt;br /&gt;
       $ mysql.server stop&lt;br /&gt;
&lt;br /&gt;
   3. Edit /opt/zimbra/conf/localconfig.xml to update the following password values to the values&lt;br /&gt;
      from the localconfig.xml file on the old server:&lt;br /&gt;
      Mysql passwords :&lt;br /&gt;
          ▪ zimbra_mysql_password&lt;br /&gt;
          ▪ mysql_root_password&lt;br /&gt;
&lt;br /&gt;
  LDAP password values:&lt;br /&gt;
&lt;br /&gt;
       ◦   ldap_amavis_password&lt;br /&gt;
       ◦   ldap_nginx_password&lt;br /&gt;
       ◦   ldap_postfix_password&lt;br /&gt;
       ◦   ldap_replication_password&lt;br /&gt;
       ◦   ldap_root_password&lt;br /&gt;
       ◦   zimbra_ldap_password&lt;br /&gt;
&lt;br /&gt;
   4. Moving the email store and index:&lt;br /&gt;
      Rsync the /opt/Zimbra/store/* and /opt/Zimbra/index/*&lt;br /&gt;
&lt;br /&gt;
4.4 Stop Zimbra on old live server .&lt;br /&gt;
4.5 On New server&lt;br /&gt;
       • Assign the IP to the new server. Add the external ldap, and public IPs in the /etc/hosts file.&lt;br /&gt;
       • Change the IP in the named.conf and forward zone file.&lt;br /&gt;
       • Sync both transport files and postmap it.&lt;br /&gt;
4.6 Zimbra is Live on New server.&lt;br /&gt;
&lt;br /&gt;
Release 8.8.15_GA_3953.RHEL8_64_20200629025823 RHEL8_64 FOSS edition, Patch 8.8.15_P39.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
All the Zimbra services are running&lt;br /&gt;
&lt;br /&gt;
Emails sent in the year 2012 and received in 2013 successfully migrated to new server.&lt;br /&gt;
&lt;br /&gt;
Zimbra logo successfully replaced by IIEST SHIBPUR Logo&lt;br /&gt;
&lt;br /&gt;
Installing DRBD on both the nodes :&lt;br /&gt;
  DRBD (Distributed Replicated Block Device) is a software-based, shared-nothing, replicated&lt;br /&gt;
  storage solution mirroring the content of block devices (hard disks, partitions, logical volumes etc.)&lt;br /&gt;
  between hosts.&lt;br /&gt;
&lt;br /&gt;
  DRBD mirrors data:&lt;br /&gt;
&lt;br /&gt;
  in real time: Replication occurs continuously while applications modify the data on the device.&lt;br /&gt;
  transparently: Applications need not be aware that the data is stored on multiple hosts.&lt;br /&gt;
  synchronously: With synchronous mirroring, applications are notified of write completions after&lt;br /&gt;
  the writes have been carried out on all (connected) hosts.&lt;br /&gt;
&lt;br /&gt;
  Install DRBD 9.0 from ELREPO&lt;br /&gt;
  To install ELREPO, first you should import the GPG key or else the GPG check will fail later.&lt;br /&gt;
&lt;br /&gt;
  # rpm --import https://www.elrepo.org/RPM-GPG-KEY-elrepo.org&lt;br /&gt;
&lt;br /&gt;
  Next install the ELPO repo&lt;br /&gt;
&lt;br /&gt;
  # rpm -Uvh https://www.elrepo.org/elrepo-release-8.el8.elrepo.noarch.rpm&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  Once the elpo-release rpm is installed on both the nodes, use dnf to lookup drbd package&lt;br /&gt;
&lt;br /&gt;
  # dnf search drbd&lt;br /&gt;
============================================================== Name &amp;amp;&lt;br /&gt;
Summary Matched: drbd&lt;br /&gt;
===============================================================&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
kmod-drbd90.x86_64 : drbd90 kernel module(s)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
collectd-drbd.x86_64 : DRBD plugin for collectd&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
drbd90-utils.x86_64 : Management utilities for DRBD&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
drbd90-utils-sysvinit.x86_64 : The SysV initscript to manage the DRBD.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
drbdlinks.noarch : Program for managing links into a DRBD shared&lt;br /&gt;
partition&lt;br /&gt;
&lt;br /&gt;
    Install the DRBD 9 packages&lt;br /&gt;
    # dnf install kmod-drbd90.x86_64 drbd90-utils.x86_64 -y&lt;br /&gt;
5   Configuring DRBD&lt;br /&gt;
&lt;br /&gt;
    •   Configure a simple global_common.conf&lt;br /&gt;
&lt;br /&gt;
         # vi /etc/drbd.d/global_common.conf&lt;br /&gt;
global {&lt;br /&gt;
 usage-count no;&lt;br /&gt;
}&lt;br /&gt;
common {&lt;br /&gt;
 net {&lt;br /&gt;
  protocol C;&lt;br /&gt;
 }&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
    •   usage-count :-&lt;br /&gt;
        The usage-count no line in the global section skips sending a notice to the DRBD team each&lt;br /&gt;
        time a new version of the software is installed in your system.&lt;br /&gt;
&lt;br /&gt;
    •   protocol C :-&lt;br /&gt;
        The protocol C line tells the DRBD resource to use a fully synchronous replication.&lt;br /&gt;
        This means that local write operations on the node that is functioning as primary are&lt;br /&gt;
        considered completed only after both the local and remote disk writes have been confirmed.&lt;br /&gt;
        Thus, if we run into the loss of a single node, that should not lead to any data loss under&lt;br /&gt;
        normal circumstances, unless both nodes (or their storage subsystems) are irreversibly&lt;br /&gt;
        destroyed at the same time.&lt;br /&gt;
&lt;br /&gt;
Create DRBD resource :-&lt;br /&gt;
&lt;br /&gt;
         # vi /etc/drbd.d/drbd1.res&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
   •   By default DRBD uses port between 7788-7790, we have explicitly defined port number as&lt;br /&gt;
       7789.&lt;br /&gt;
   •   Our DRBD device resource would be /dev/drbd1 i.e. the logical volumes from all the cluster&lt;br /&gt;
       nodes would use /dev/drbd1 to perform Linux disk replication&lt;br /&gt;
   •   Next we must copy the DRBD resource file to all the cluster nodes&lt;br /&gt;
&lt;br /&gt;
•   When we installed DRBD earlier, a utility called drbdadm was installed as well,&lt;br /&gt;
    drbdadm is intended to be used for the administration of DRBD resources.&lt;br /&gt;
&lt;br /&gt;
•   Create the meta-data –&lt;br /&gt;
    # drbdadm create-md drbd1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
    The first step of Linux Disk Replication in starting and bringing a DRBD resource online is to&lt;br /&gt;
    initialize its metadata&lt;br /&gt;
&lt;br /&gt;
    So our DRBD device /dev/drbd1 is ready.&lt;br /&gt;
&lt;br /&gt;
•   Repeat the same steps on both the nodes for DRBD configuration.&lt;br /&gt;
&lt;br /&gt;
•   Check DRBD Device status&lt;br /&gt;
&lt;br /&gt;
•   # drbdadm status drbd1 – It will show as secondary, we will have to force it to make it primary.&lt;br /&gt;
&lt;br /&gt;
•   Make the node1 as primary&lt;br /&gt;
    # drbdadm primary --force drbd1&lt;br /&gt;
&lt;br /&gt;
•   # drbdadm status drbd1 – It will show node1 as primary, but inconsistent as we have not&lt;br /&gt;
    connected and synced the node2 yet.&lt;br /&gt;
&lt;br /&gt;
•   Format to ext4 file system&lt;br /&gt;
    # mkfs.ext4 /dev/drbd1&lt;br /&gt;
&lt;br /&gt;
•   Mount /dev/drbd1 on /opt inside which we have Zimbra installed and configured.&lt;br /&gt;
    # mount /dev/drbd1 /opt&lt;br /&gt;
•&lt;br /&gt;
•   # drbdadm connect all – to connect both the nodes.&lt;br /&gt;
    It will start the syncing from primary to secondary node.&lt;br /&gt;
&lt;br /&gt;
•   # drbdsetup status --statistics --verbose drbd1 – this will show the detailed status and&lt;br /&gt;
    percentage of data synced from primary to secondary node.&lt;br /&gt;
&lt;br /&gt;
•   After sync completion both the nodes are displayed as “UpToDate”&lt;br /&gt;
&lt;br /&gt;
Configuration of Spam Filtering&lt;br /&gt;
&lt;br /&gt;
  1.1    Outright Blocking With Postfix DNS Protocol&lt;br /&gt;
     Checks&lt;br /&gt;
&lt;br /&gt;
  zmprov mcf +zimbraMtaRestriction reject_non_fqdn_sender&lt;br /&gt;
  zmprov mcf +zimbraMtaRestriction reject_unknown_sender_domain&lt;br /&gt;
  zmprov mcf +zimbraMtaRestriction reject_unknown_reverse_client_hostname&lt;br /&gt;
&lt;br /&gt;
  The “reject_unknown_sender_domain” according to the Postfix documentation, performs some&lt;br /&gt;
  specific checks to ensure the sender’s domain actually exists in public DNS. If the sender’s domain&lt;br /&gt;
  doesn’t exist, the email is not accepted. Similarly, the “reject_non_fqdn_sender” check will reject&lt;br /&gt;
  the email if the MAIL FROM isn’t a properly-formed email address.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  1.2         Outright Blocking of Bad Sending Servers&lt;br /&gt;
  Now we start using blocklists within Postfix, and their are two kinds: “RBLs” or left-hand-side&lt;br /&gt;
  blocklists, and RHSBLs or right-hand-side blocklists. RBLs list IP addresses; RHSBLs list domains.&lt;br /&gt;
&lt;br /&gt;
  zmprov mcf +zimbraMtaRestriction &amp;quot;reject_rbl_client b.barracudacentral.org&amp;quot;&lt;br /&gt;
&lt;br /&gt;
  Here, we use a free block list from Barracuda.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  1.3         Outright Blocking of Certain Attachments&lt;br /&gt;
      By default, Zimbra does not block what could be dangerous email attachments, like Visual&lt;br /&gt;
      Basic scripts, Windows Registry edits etc. So, we need to block those attachments&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
      zmprov mcf +zimbraMtaBlockedExtension asd&lt;br /&gt;
      zmprov mcf +zimbraMtaBlockedExtension bat&lt;br /&gt;
      zmprov mcf +zimbraMtaBlockedExtension cab&lt;br /&gt;
      zmprov mcf +zimbraMtaBlockedExtension chm&lt;br /&gt;
      zmprov mcf +zimbraMtaBlockedExtension cmd&lt;br /&gt;
      zmprov mcf +zimbraMtaBlockedExtension com&lt;br /&gt;
      zmprov mcf +zimbraMtaBlockedExtension cpl&lt;br /&gt;
      zmprov mcf +zimbraMtaBlockedExtension cpgz&lt;br /&gt;
&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension dll&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension do&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension exe&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension hlp&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension hta&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension html&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension js&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension jse&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension lnk&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension ocx&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension pif&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension reg&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension scr&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension shb&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension shm&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension shs&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension shtml&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension vbe&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension vbs&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension vbx&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension vxd&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension wsf&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension wsh&lt;br /&gt;
zmprov mcf +zimbraMtaBlockedExtension xl&lt;br /&gt;
zmprov mcf zimbraMtaBlockedExtensionWarnAdmin TRUE&lt;br /&gt;
zmprov mcf zimbraMtaBlockedExtensionWarnRecipient TRUE&lt;br /&gt;
zmprov mcf zimbraVirusBlockEncryptedArchive FALSE&lt;br /&gt;
&lt;br /&gt;
1.4     Enforcing a match between FROM address and&lt;br /&gt;
   sasl username&lt;br /&gt;
&lt;br /&gt;
  Update zimbraMtaSmtpdRejectUnlistedRecipient &amp;amp; zimbraMtaSmtpdRejectUnlistedSender&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  zmprov mcf zimbraMtaSmtpdRejectUnlistedRecipient yes&lt;br /&gt;
  zmprov mcf zimbraMtaSmtpdRejectUnlistedSender yes&lt;br /&gt;
  zmmtactl restart&lt;br /&gt;
  zmconfigdctl restart&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  Set the zimbraMtaSmtpdSenderLoginMaps portion&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  zmprov mcf zimbraMtaSmtpdSenderLoginMaps proxy:ldap:/opt/zimbra/conf/ldap-slm.cf&lt;br /&gt;
  +zimbraMtaSmtpdSenderRestrictions reject_authenticated_sender_login_mismatch&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  Edit the file smtpd_sender_restrictions&lt;br /&gt;
  You need to edit the file opt/zimbra/conf/zmconfigd/smtpd_sender_restrictions.cf and add&lt;br /&gt;
  after the permit_mynetworks the line reject_sender_login_mismatch&lt;br /&gt;
&lt;br /&gt;
  vi /opt/zimbra/conf/zmconfigd/smtpd_sender_restrictions.cf&lt;br /&gt;
&lt;br /&gt;
  zmconfigd will update the postfix configuration automatically and apply the new rules. Now if&lt;br /&gt;
  an account is hacked, and this is in place, they will not be able to send out emails with different&lt;br /&gt;
  &amp;quot;from&amp;quot; addresses.&lt;br /&gt;
&lt;br /&gt;
1.5      Tuning SpamTag and SpamKill&lt;br /&gt;
&lt;br /&gt;
  It is important to have updated AntiSpam Rules, updated rules will prevent the spam more&lt;br /&gt;
  effectively hence make sure to enable the below setting if it is not enabled already.&lt;br /&gt;
  $ zmlocalconfig -e antispam_enable_rule_updates=true&lt;br /&gt;
  $ zmlocalconfig -e antispam_enable_restarts=true&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
  Tune the SpamTag and SpamKill percentage.&lt;br /&gt;
&lt;br /&gt;
  zmprov mcf zimbraSpamKillPercent 75&lt;br /&gt;
&lt;br /&gt;
  zmprov mcf zimbraSpamTagPercent 25&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
1.6    Cbpolicy webui activated, and it’s authentication&lt;br /&gt;
   implemented.&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>