NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] Problem with asmtp



I could see something strange happening on the firewall.. Sometimes Firewall
is initiating connections to other mail servers on ports other than SMTP
port and the XlateSPort for them is mail/smtp. These connections are dropped
according to my rules..After 5 attempts on the same the port to the other
mail servers, there is connection dropped with rule 0 error "Unknown
established TCP packet" which is from the mail server to firewall. There are
no connections from mail server to the firewall on that port before this
event .

Could you please tell me why it is initiating the connections to the mail
server on the ports which are other than smtp and its XlateSPort?  Could you
please tell me what would be the cause for the error "Connection I/O
failure"? Please check the below mail for the log file.

Thanks a lot in advance,
 -Srinivas B.

>  -----Original Message-----
> From:         Srinivasa Rao Bandaru
> Sent: 12 April 2002 15:25
> To:   '[email protected]'
> Subject:      Problem with asmtp
>
> Hi,
>       I am facing a peculiar problem with the asmtpd daemon on my
> firewall. It doesn't accept any smtp connections  for about two minutes at
> random intervals.. I guess this random interval is based on the smtp load
> on the firewall. I have enabled debugging on in.asmtp to log all the
> details. The log from asmtp.elg is shown below, when it is not accepting
> any more connections.. Can someone please give me any hint on this to
> resolve the problem?
>
> Matched rule # 22
> SMTP_CliInfo::reset(): renamed file
> 11:46:50 fd: 14 src: 204.4.182.10 dst: 212.36.174.188   Connection I/O
> failure.
> Connection closed: indx #6
> SmtpSession::reset: (fd:= 13) Trying to get destination from
> map_auth_conn...
> New connection: fd 13, indx #4
> SmtpSession::reset: (fd:= 14) Trying to get destination from
> map_auth_conn...
> New connection: fd 14, indx #5
> new array size is 19
> new array size is 29
> resolver_gethostbyaddr() failed to find hostname for src 62.189.28.221
> Matched rule # 22
> SMTP_CliInfo::reset(): renamed file
> Connection closed: indx #5
> new array size is 19
>
> In SMTP_CliInfo::operator=()
> In SMTP_CliInfo::operator=()
> In SMTP_CliInfo::operator=()
> In SMTP_CliInfo::operator=()
> In SMTP_CliInfo::operator=()
> clients buffer expanded; new size: 74 number of clients: 64
> SmtpSession::reset: (fd:= 75) Trying to get destination from
> map_auth_conn...
> New connection: fd 75, indx #64
> SmtpSession::reset: (fd:= 76) Trying to get destination from
> map_auth_conn...
> New connection: fd 76, indx #65
> SmtpSession::reset: (fd:= 77) Trying to get destination from
> map_auth_conn...
> New connection: fd 77, indx #66
> SmtpSession::reset: (fd:= 78) Trying to get destination from
> map_auth_conn...
> New connection: fd 78, indx #67
> SmtpSession::reset: (fd:= 79) Trying to get destination from
> map_auth_conn...
> New connection: fd 79, indx #68
> 11:54:06 fd: 79 src: x.x.x.x dst: 192.168.30.253   Connection prematurely
> closed.
> Connection closed: indx #68
> Matched rule # 22
> Matched rule # 17
> Matched rule # 22
>
> Thanks a lot in advance,
>  -Srinivas B.


This message is confidential and may also be legally privileged.  If you are not the intended recipient, please notify us immediately.  You should not copy it or use it for any purpose, not disclose its contents to any other person.  The views and opinions expressed in this e-mail message are the author's own and may not reflect the views and opinions of Wilco.

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.