Great Circle Associates Firewalls
(November 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: How do Firewalls deal with the Ident Protocol?
From: Peter Newman <Peter . Newman @ hcn . net . au>
Date: Mon, 01 Dec 1997 13:26:03 +1000
To: firewalls @ greatcircle . com

Hi,

I was recently troubleshooting some SMTP and POP server problems
particularly dealing with firewall interaction.  A client of ours was
hidden behind a firewall and was having some difficulty trying to use our
SMTP and POP servers.  Now we have other clients behind other firewalls
which have absolutely no trouble using these services.  However after some
debugging we determined that authentication requests were timing out on
port 113 (refer to rfc1413) at his firewall.  So I disabled this request
needed by our POP server and set the timeout on our SMTP server to be much
less then the default 30 seconds defined by the sendmail 8.8.5 MTA.

Still it strikes me that this third party vendor firewall product is not
correctly configured to send these auth checks to the correct host inside
the firewall.  Can anybody confirm this for me?

Not having a firewall background I do see conceptual problems in how
firewalls can return the auth request to the correct host - so how do
firewalls deal with the ident protocol?

Regards,
Pete.


Indexed By Date Previous: WatchGuard???
From: "kyoweon.Yoon" <kwyoon @ songrhim . co . kr>
Next:
From: (nil)
Indexed By Thread Previous: WatchGuard???
From: "kyoweon.Yoon" <kwyoon @ songrhim . co . kr>
Next:
From: (nil)

Google
 
Search Internet Search www.greatcircle.com