[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: woody firewall broken? [I was mistaken ]



> > On Fri, Jul 12, 2002 at 09:32:05AM +0200, Davi Leal wrote:
> > > I think it is due to the nessus checks that we are getting "Deferring
> > > messages" from the sendmail server; "Deferred: Connection timed out
with
> > > mx.terra.es.". What we know by sure is that using again the old
firewall
> > > the sendmail server works rightly again.
> >
> > Is your new Firewall crashed or not? Have you tried to reboot it? Nessus
> > willl most likely not damage your firewall, so rebooting will be enough.
>
> Yes, I think our new firewall is crashed. Of course I have rebooted the
> sendmail and firewall hosts. However the sendmail shows the same message.
We
> are using now the old one and the sendmail works rightly again.
>
> What happened:
>
> [Day 1] The new firewall (woody, 2.4 kernel, ReiserFS) worked rightly. We
> realized a check connecting from telephone line via our Radius server and
> sent an email rightly. Additionaly we carried out some checks sending
emails
> and checking the email server log. All was OK.

The facts show that we didnt check rightly sending email from the ISP to
outside.


> Well, I will format and reinstall the new firewall again. I am going to do
a
> 'mondo' backup copy before reintalling so as to check via "mondo
difference
> reinstalled" what happened in the firewall.

I realized the 'mondo' backup "mondoarchive -O -c 12 -d 0,0,0" and
reinstalled the new firewall. The differences "mondoarchive -Vc 16" only
shows normal things. Nothing was broken.

We know now what was the trouble. It was needed enable the UDP connection to
the SMTP host. Now it is working rightly. We have checked with and without
this filter. It seems it is needed. Without it we get the "Deferred:
Connection timed out with mx.terra.es" message.

> P.D.: Do you know if sendmail uses only 25/tcp?. /etc/services does not
> shows any 25/udp.

Regards,
Davi Leal



-- 
To UNSUBSCRIBE, email to debian-firewall-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org



Reply to: