Re: [ietf-smtp] Characteristics of Isolated (or mostly-isolated) industrial IP Networks

"John R Levine" <johnl@taugh.com> Mon, 06 January 2020 14:37 UTC

Return-Path: <johnl@taugh.com>
X-Original-To: ietf-smtp@ietfa.amsl.com
Delivered-To: ietf-smtp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F017712082A for <ietf-smtp@ietfa.amsl.com>; Mon, 6 Jan 2020 06:37:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1536-bit key) header.d=iecc.com header.b=PzXPSINK; dkim=pass (1536-bit key) header.d=taugh.com header.b=SDt2OUXZ
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id X4wZX26vWqyt for <ietf-smtp@ietfa.amsl.com>; Mon, 6 Jan 2020 06:37:18 -0800 (PST)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DE18E120823 for <ietf-smtp@ietf.org>; Mon, 6 Jan 2020 06:37:17 -0800 (PST)
Received: (qmail 57734 invoked from network); 6 Jan 2020 14:37:15 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type:user-agent; s=e183.5e13461b.k2001; i=johnl-iecc.com@submit.iecc.com; bh=6UF4t74bHzUsWYCG53yJEJhbWqtxcbs/YL0v7IIhRvU=; b=PzXPSINK+fuJjYjoTMO7zzFoUVbUnD3TBrxNXk5v6aLdFvbSphe0O+vUApY70mIzuaEwLf8iw7VBeR/cfMma3jS8JIdwoCW09TJlVQJGfhV2zM+6cOak5HmmPrCIZnFJyU+4DINEElgCLBOTNkFs6Ekj36AfItuT1ELeNECTUgDPH8NyYyK4eCYrpPwu7kkF7Ufr5xI5wFEkfBUPRGH9h0TwB3JqN95AirCUBxabg11vPyTUSrcnqRk2gqSMiQ2O
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:references:mime-version:content-type:user-agent; s=e183.5e13461b.k2001; olt=johnl-iecc.com@submit.iecc.com; bh=6UF4t74bHzUsWYCG53yJEJhbWqtxcbs/YL0v7IIhRvU=; b=SDt2OUXZ56xESGkohkDrNoZgl0qCgsxpUORcNDrFqCWNks275vwfvm7xK+ZKFyEMUbHT8WXCKJqYl0eXObVUZlJ9osObjeKBn6NKTELxUKNcH+BifYIxevHYDkCziVbrvaPoGcuMCC5xhijJ+MlZO1Uz8pWBZtzi7HTlpIppOj70MRtNFuZA0xRQZQEDNtoL/IU/pmjMX4PEvuk1NDpF38T+AYeB+JXiwFt2EkljnQszqUjSIcLGIafnbCQuXefV
Received: from localhost ([IPv6:2001:470:1f07:1126::78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126::78:696d:6170]) with ESMTPSA (TLS1.3 ECDHE-RSA AES-256-GCM AEAD, johnl@iecc.com) via TCP6; 06 Jan 2020 14:37:15 -0000
Date: Mon, 06 Jan 2020 09:37:14 -0500
Message-ID: <alpine.OSX.2.21.99999.374.2001060936300.73172@ary.qy>
From: John R Levine <johnl@taugh.com>
To: dcrocker@bbiw.net
Cc: ietf-smtp@ietf.org
In-Reply-To: <8119b1ec-354a-875b-f015-839c412eb900@dcrocker.net>
References: <20200105171930.0054211FC46D@ary.qy> <8119b1ec-354a-875b-f015-839c412eb900@dcrocker.net>
User-Agent: Alpine 2.21.99999 (OSX 374 2019-10-27)
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-smtp/z9B5HRgdSQ-sDeIHBCQIQtQqOJk>
Subject: Re: [ietf-smtp] Characteristics of Isolated (or mostly-isolated) industrial IP Networks
X-BeenThere: ietf-smtp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Discussion of issues related to Simple Mail Transfer Protocol \(SMTP\) \[RFC 821, RFC 2821, RFC 5321\]" <ietf-smtp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf-smtp>, <mailto:ietf-smtp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-smtp/>
List-Post: <mailto:ietf-smtp@ietf.org>
List-Help: <mailto:ietf-smtp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-smtp>, <mailto:ietf-smtp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Jan 2020 14:37:20 -0000

> On 1/5/2020 9:19 AM, John Levine wrote:
>> In article <3c50a793-dd26-3254-f9e3-b642793918b7@dcrocker.net> you write:
>>> What else is distinctive?
> ...
>> If it sent mail to any other address, or if the message rate was much above
>> one a minute, we'd know something was screwed up with its mail.
>
> This sounds like a variant of blocking outbound port 25.

It's exactly forcing all the mail through the submission host so it can do 
outbound filtering.  That's been common on consumer mail systems for 
decades.

Regards,
John Levine, johnl@taugh.com, Taughannock Networks, Trumansburg NY
Please consider the environment before reading this e-mail. https://jl.ly