This documentation is for Dovecot v2.x, see wiki1 for v1.x documentation.

Allow_nets extra field

This is a comma separated list of IPs and/or networks where the user is allowed to log in from. If the user tries to log in elsewhere, the authentication will fail the same way as if a wrong password was given.

Example: allow_nets=127.0.0.0/8,192.168.0.0/16,1.2.3.4,4.5.6.7.

IPv6 addresses are also allowed. IPv6 mapped IPv4 addresses (eg. ::ffff:1.2.3.4) are converted to standard IPv4 addresses before matching. Example: allow_nets=::1,2001:abcd:abcd::0:0/80,1.2.3.4

passwd-file example

user:{plain}password::::::allow_nets=192.168.0.0/24

Keyword 'local'

The keyword 'local' is accepted for Non-IP connections like Unix socket. For example, with a Postfix/LMTP delivery setup, you must include 'local' for Postfix to verify the email account:

passdb {
  driver = static
  args = password=test allow_nets=local,127.0.0.1/32
}

Otherwise, you will see this error in the log:

[/var/run/dovecot/lmtp] said: 550 5.1.1 <test2@example.com> User doesn't exist: test2@example.com (in reply to RCPT TO command))

PasswordDatabase/ExtraFields/AllowNets (last edited 2016-08-03 15:42:56 by cpe-172-248-92-191)