[suse-security] SuSEfirewall2 and MTA in a DMZ


i have a problem using my two mailserver (qmail & imail) in my DMZ. Any server 
can receive/send mails from his clients and receive mails from other MTA.

But when a client send a mail to a non-local domain (a other MTA) they'll be 
dropped by a 'SuSE-FW-DROP-DEFAULT' - Rule. The MTA brigns then 'Error Stack 
Connect' or 'MX Connect Fail' (e.g. IMail).

"Hmmm... then open port 25".... right, this is done. And I can sent email to 
any MTA over my customers virtual domain, but the customers can't do...

Now my question is...  what is wrong in my SuSEfirewall2 Skript??? Where can I 
look for?



