Topic: Roundcube - block from internet while allow SMTPS and lets encrypt
Hi iRedmail team,
I recently migarted from old iRedmail to new iRedmail 1.7.2 and mail transfer was done properly and setup is working. It is also setup with Lets encrypt certificate so that Secure IMAP and Secure SMTP to access from mail clients from phones/tablets when outside (from internet).
I can access HTTPS Roundcube Webmail from local LAN and from internet.
All the accesses are working as expected and spam situation/filtering is also working well (improved now).
My question:
I want to disable "Roundcube Webmail" from internet for security reasons and only allow from LAN (or when VPN in). How can I do this?
My Internet router (Synology_RT2600AC) does provide a basic firewall and done port forwarding for port 80, 443, 587 & 993.
Port 80 and 443 is required for lets encrypt to work. Therefore, it is not possible to block 80 and 443 to stop access Roundcube from internet.
==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====
- iRedMail version (check /etc/iredmail-release): iRedMail-1.7.2
- Deployed with iRedMail Easy or the downloadable installer? - Downloadable installer
- Linux/BSD distribution name and version: Ubuntu 24.04.2 LTS
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): Nginx
- Manage mail accounts with iRedAdmin-Pro? No, iRedAdmin (none-pro)
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.