From 650db94b3b8dc6665c3883ac29f78adfe23e03f0 Mon Sep 17 00:00:00 2001 From: Guilhem Moulin Date: Tue, 14 Jan 2014 06:51:03 +0100 Subject: Don't use IPSec to relay messages to localhost. --- roles/MSA/templates/etc/postfix/main.cf.j2 | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'roles/MSA') diff --git a/roles/MSA/templates/etc/postfix/main.cf.j2 b/roles/MSA/templates/etc/postfix/main.cf.j2 index 685287a..337acd1 100644 --- a/roles/MSA/templates/etc/postfix/main.cf.j2 +++ b/roles/MSA/templates/etc/postfix/main.cf.j2 @@ -64,7 +64,11 @@ header_checks = pcre:$config_directory/anonymize_sender.pcre # Tunnel everything through IPSec smtp_tls_security_level = none +{% if 'MTA-out' in group_names %} +smtp_bind_address = 127.0.0.1 +{% else %} smtp_bind_address = 172.16.0.1 +{% endif %} # TLS smtpd_tls_security_level = encrypt -- cgit v1.2.3