Posfix and Amavisd-new in FreeBSD jail

Valeri Galtsev galtsev at kicp.uchicago.edu
Thu Jun 28 14:48:59 UTC 2018

On 06/28/18 08:35, James B. Byrne via freebsd-questions wrote:
> Dose anyone on the list run Postfix with amavisd inside a FreeBSD
> jail? 

On larger servers I switched to maia (to the contrary to what I said 
earlier, one can configure and run it, not not only the way port 
maintainer has it, Thanks to port maintainer !!). One of the servers 
fully running in jail may at some point get passed to the project owner 
to [co]-administer it, for this reason it has 

> I am running into this problem:
> /usr/local/sbin/amavisd[42231]: (!)DENIED ACCESS from IP,
> policy bank ''

In my case jail has localhost IP, but I set jails "by the 
book", I do not use any scripts like ezjail... jail doesn't need to talk 
to localhos of host system. You may want to go though

( and maybe /usr/local/etc/postfix/main.cf, depending on how you have 
amavis harnessed in postfix)

and change localhost's IP referenced in their configurations to

(like in master.cf:

smtp      inet  n       -       n       -       -       smtpd
         -o content_filter=smtp-amavis:[]:10024

check that that IP is covered in amavis access control list in 

@inet_acl = qw( [::1] ... )

and you can test them one at a time from shell in that jail by

telnet 10024

and do all SMTP commands, see where you are thrown out.

I hope, this helps.


> The cloned lo interface used by the jail is assigned address
> lo2: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
> 	inet netmask 0xffffffff
> 	inet6 ::32 prefixlen 128
> 	groups: lo
> The postfix and amavisd configuration files refer only to
> The hosts file contains this:
> ::1               localhost localhost.harte-lyne.ca
>         localhost localhost.harte-lyne.ca
> Does anyone have this working properly inside a jail.  What do I need
> to do to get it to work?

Valeri Galtsev
Sr System Administrator
Department of Astronomy and Astrophysics
Kavli Institute for Cosmological Physics
University of Chicago
Phone: 773-702-4247

