]> git.proxmox.com Git - pmg-docs.git/blame - pmg-administration.adoc
administration: add a basic explanation about personal quarantine
[pmg-docs.git] / pmg-administration.adoc
CommitLineData
e3eaa56a
DM
1Administration
2==============
3
70dc6dd1
OB
4The Administration GUI allows you to do common tasks
5such as updating software packages, managing quarantine, viewing service
6status, and managing mail queues. It also provides server statistics in
e3eaa56a
DM
7order to verify server health.
8
9
10Server Administration
11---------------------
12
13Server status
14~~~~~~~~~~~~~
15
a695a527 16[thumbnail="pmg-gui-server-status.png", big=1]
e3eaa56a
DM
17
18This page shows server statistics about CPU, memory, disk and network
19usage. You can select the displayed time span on the upper right.
20
21Administrators can open a terminal window using the 'Console'
22button. It is also possible to trigger a server 'Restart' or
23'Shutdown'.
24
25
26Services
27~~~~~~~~
28
a695a527 29[thumbnail="pmg-gui-service-status.png", big=1]
e3eaa56a
DM
30
31This panel lists all major services used for mail processing and
32cluster synchronization. If necessary, you can start, stop or restart
33them. The 'Syslog' button shows the system log filtered for the
34selected service.
35
36Please note that {pmg} uses {systemd} to manage services, so you can
37also use the standard `systemctl` command line tool to manage or view
38service status, for example:
39
40-----
41systemctl status postfix
42-----
43
44
45Updates
46~~~~~~~
47
a695a527 48[thumbnail="pmg-gui-updates.png", big=1]
e3eaa56a
DM
49
50We release software updates on a regular basis, and it is recommended
51to always run the latest available version. This page shows the
70dc6dd1 52available updates, and administrators can run an upgrade by pressing
e3eaa56a
DM
53the 'Upgrade' button.
54
55See section xref:pmg_package_repositories[Package Repositories] for
56details abaout available package repositories.
57
58
59Syslog and Tasks
60~~~~~~~~~~~~~~~~
61
a695a527 62[thumbnail="pmg-gui-syslog.png", big=1]
e3eaa56a 63
70dc6dd1 64The syslog page gives you a quick real-time log view. You can use the
80034065 65xref:pmg_tracking_center[Tracking Center] to search the logs.
e3eaa56a
DM
66
67
68Quarantine
69----------
70
71Spam
72~~~~
73
a695a527 74[thumbnail="pmg-gui-spam-quarantine.png", big=1]
3f02fc6b
DM
75
76This panel lets you inspect the mail quarantine. Emails can be safely
77previewed and if desired, delivered to the original user.
78
79The email preview on the web interface is very secure as malicious
80code (attacking your operating system or email client) is removed by
70dc6dd1 81{pmg}.
3f02fc6b 82
515eeac8
OB
83Users can get access to their personalized quarantine via the daily
84spam report, or by logging in with their LDAP credentials.
85
86Alternatively you can enable the link on Quarantine Login page. There users will get
87a link to their personalized quarantine.
88To enable this on the Quarantine Login page, edit `/etc/pmg/pmg.conf` (see section xref:pmgconfig_spamdetector_quarantine[Spam Detector Configuration - Quarantine])
89
e3eaa56a
DM
90
91Virus
92~~~~~
93
3f02fc6b
DM
94Allows administrators to inspect quarantined virus mails.
95
e3eaa56a 96
f7d90c0a
DC
97Attachment
98~~~~~~~~~~
99
100Allows administrators to inspect quarantined mails and download their
101attachments or deliver/delete them.
102
103NOTE: Use the options of the 'Remove attachment' action to control the Attachment Quarantine.
104
105
4a08dffe 106[[pmg_userblackwhitelist]]
e3eaa56a
DM
107User White- and Blacklist
108~~~~~~~~~~~~~~~~~~~~~~~~~
109
3f02fc6b
DM
110This is mostly useful to debug or verify white- and blacklist user
111settings. The administrator should not change these values because
112users can manage this themselves.
113
e3eaa56a 114
80034065 115[[pmg_tracking_center]]
e3eaa56a
DM
116Tracking Center
117---------------
118
a695a527 119[thumbnail="pmg-gui-tracking-center.png", big=1]
b0a8e83b 120
e30d2fb3
DM
121Email processing is a complex task and involves several service
122daemons. Each daemon logs information to the syslog service. The
70dc6dd1 123problem is that a server analyzes many emails in parallel, so it is
e30d2fb3
DM
124usually very hard to find all logs corresponding to a specific mail.
125
70dc6dd1 126The Tracking Center simplifies the search for
395d1740
TL
127emails dramatically. We use highly optimized and safe Rust footnote:[A language
128empowering everyone to build reliable and efficient software.
129https://www.rust-lang.org/] code to search the available syslog data. This is
130very fast and powerful, and works for sites processing several million emails
131per day.
e30d2fb3
DM
132
133The result is a list of received mails, including the following data:
134
135[cols="s,5d"]
136|====
137|Time | Timestamp of first found syslog entry.
138|From | Envelope 'From' address (the sender).
139|To | The email receiver address.
140|Status | Delivery status.
141|Syslog | The corresponding syslog entries are shown if you double click such
142entry, or if you press the '+' button on the left.
143|====
144
70dc6dd1 145You can specify filters, and most importantly you can set
e30d2fb3 146a 'Start' and 'End' time. By default the start time is set to one hour
70dc6dd1
OB
147ago. If you still get too many entries, you can try to restrict
148the search to a specific sender or receiver address, or search for a
e30d2fb3 149specific text in the logs ('Filter' entry).
e3eaa56a 150
70dc6dd1 151NOTE: Search is faster if you use a shorter time interval.
268f309d 152
70dc6dd1 153The 'Status' field summarizes what happened with an email. {pmg} is a
f29824e9 154mail proxy, meaning that the proxy receives mails from outside,
70dc6dd1 155processes them and finally sends the result to the receiver.
f29824e9
DM
156
157The first phase is receiving the mail. The proxy may reject the mail
158early, or instead accepts the mail and feeds it into the filter. The filter
159rules can block or accept the mail.
160
161In the second phase, accepted mails need to be delivered to the
70dc6dd1 162receiver. This action may also fail or succeed. 'Status'
6abb9ee3
ML
163combines the result from the first and second phase.
164
f29824e9
DM
165[options="header",cols="2s,1d,5d"]
166|====
167|Status |Phase |Description
168|rejected |1 | Email rejected (e.g. sender IP is listed on a IP blacklist)
169|greylisted |1 | Email temporarily rejected by greylisting
170|queued/deferred |1 | Internal Email was queued, still trying to deliver
70dc6dd1 171|queued/bounced |1 | Internal Email was queued but not accepted by the target email server (for example user unknown)
7b238f73 172|queued/delivered |1 | Internal Email was queued and delivered
70dc6dd1 173|quarantine |1 | Email was moved to quarantine
f29824e9
DM
174|blocked |1 | Email was blocked by filter rules
175|accepted/deferred |2 | Email accepted, still trying to deliver
70dc6dd1 176|accepted/bounced |2 | Email accepted but not accepted by the target email server (for example user unknown)
6abb9ee3 177|accepted/delivered |2 | Email accepted and delivered
f29824e9
DM
178|====
179
7b7e406b 180[[postfix_queue_administration]]
e3eaa56a
DM
181Postfix Queue Administration
182----------------------------
183
0972c942 184[thumbnail="pmg-gui-queue-admin-summary.png", big=1]
f2bd0439
SI
185
186Mail-queues are one of the central concepts of the SMTP protocol. Once a
187mailserver accepts a mail for further processing it saves it to a queue.
188After the mail is either relayed to another system, stored locally
7b7e406b 189or discarded, it is deleted from the local mail-queue.
f2bd0439
SI
190
191If immediate processing is not possible, for example because a downstream
192mailserver is not reachable, the mail remains on the queue for later
193processing.
194
0972c942 195The 'Queue Administration' panel provides a summary about the current state
7b7e406b 196of the postfix mail-queue, similar to the 'qshape (1)' command-line utility.
f2bd0439 197
7b7e406b 198It shows domains for which mails were not delivered, and how long they have
f2bd0439
SI
199been queued.
200
201The three Action Buttons on top provide the most common queue operations:
202
203'Flush Queue'::
204
205Attempt to deliver all currently queued mail, for example if a downstream
206server has become available again.
207
208'Delete All Messages'::
209
210Delete all currently queued mail, for example if the queue contains only spam.
f2bd0439
SI
211
212'Discard address verification database'::
213
214Clear the recipient verification cache.
215
0972c942
TL
216A sudden increase of queued mails should be checked out closely. It can
217indicate issues connecting to downstream servers.
218This can also mean that one of the servers for which you relay emails sends
219spam itself.
f2bd0439 220
0972c942
TL
221Deferred Mail
222~~~~~~~~~~~~~
223[thumbnail="pmg-gui-queue-admin-deferred.png"]
224
225In the 'Deferred Mail' tab you can examine each deferred email separately.
226Besides providing the contact information about sender and receiver you can
227also check the reason for an email being still queued.
228
229You can view the complete headers and filter by sender or receiver of queued up
230mails.
231
232Here you can also flush or delete each deferred email independently.