Great Circle Associates Firewalls
(March 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: ipfwadm and smtp connections
From: "Mark Horn [ Net Ops ]" <mhorn @ funb . com>
Date: Mon, 10 Mar 1997 09:37:07 -0500
To: Todd Graham Lewis <lists @ reflections . eng . mindspring . net>
Cc: m* <mark @ novare . net>, firewalls @ GreatCircle . COM
In-reply-to: <Pine . LNX . 3 . 95q . 970310035834 . 12288A-100000 @ reflections . eng . mindspring . net>; from Todd Graham Lewis on Mon, Mar 10, 1997 at 03:59:38AM -0500
References: <3323C21C . 65395D96 @ novare . net> <Pine . LNX . 3 . 95q . 970310035834 . 12288A-100000 @ reflections . eng . mindspring . net>

Todd Graham Lewis says:
>On Mon, 10 Mar 1997, m* wrote:
>
>> hey all,
>> 
>> i have implemented a firewall using a 486/DX2 running linux ver. 2.0.6.
>> with reat success with one exception:
>> 
>> smtp connections through the firewall to our mail server are 
>> ridiculously slow, like 25 seconds before the connection and xfer
>> completes. needless to say, this is unacceptable.
>> 
>> all of the other protocols handled by the f-wall are not affected.
>
>I guess that the mail server is trying to resolve the name of the
>delivering agent, but name service is being impaired by your firewall
>setup.  Do you have DNS working properly on your SMTP host?

Another possibility is that the mail server is running a version of
sendmail that tries to do an ident call prior to accepting the connection.
Check the firewall logs.  If it's dropping connections from the mail server
to the firewall on port 113, then it's the ident problem.  

Sendmail on the mailserver will receive a connection and try and figure
out who originated that connection.  In some cases it does this by using
ident.  It will open a TCP port back to the originator of the email
connection.  If that originator is a firewall, that packet will normally
get dropped.  The sendmail that initiated it will have to wait for the
connection to timeout before proceeding on with the connection.

FYI,
-- 
Mark Horn <mhorn @
 funb .
 com>

PGP Public Key available from: http://www.es.net/hypertext/pgp.html
PGP KeyID/fingerprt: 00CBA571/32 4E 4E 48 EA C6 74 2E  25 8A 76 E6 04 A1 7F C1

Attachment: pgpIel1xGGkIE.pgp
Description: PGP signature


Follow-Ups:
References:
Indexed By Date Previous: Re: plug-gw and tis and ipfs
From: "Scott W. Tyree" <swtyree @ super . org>
Next: Re: Mainframe - SNA Security in the internet environment.
From: Kevin Bowman <kbowman @ garmin . com>
Indexed By Thread Previous: Re: ipfwadm and smtp connections
From: Todd Graham Lewis <lists @ reflections . eng . mindspring . net>
Next: Re: ipfwadm and smtp connections
From: m* <mark @ novare . net>

Google
 
Search Internet Search www.greatcircle.com