From: "Michael Hudin" <hudin@zoetrope.com>
To: netfilter@lists.samba.org
Subject: Re: Outgoing SMTP Mystery
Date: Wed, 5 Jun 2002 11:21:09 -0700 [thread overview]
Message-ID: <003a01c20cbd$c3ca9120$5227a8c0@michael> (raw)
In-Reply-To: 3A5DC36EC1506C40825C05BE65E62AEF0E79EC@neptuno.idea.com.mx
That would be a good way to test. Unfortunately I don't have telnet setup
on any machines that are external to the firewall and have qmail running.
When I went to port 25 using telnet, it did appear to authenticate me
through one of the usernames, but I may be mistaken since I'm not very
knowledgeable about telnet.
Omar, thanks for the offlist help with the port forwarding by the way. This
has to be one of the useful and helpful groups of people out there.
-michael
----- Original Message -----
From: "Omar Castaneda Acosta" <omar@idea.com.mx>
To: "Michael Hudin" <hudin@zoetrope.com>
Sent: Wednesday, June 05, 2002 11:03 AM
Subject: RE: Outgoing SMTP Mystery
Well, if you can connect to port 25 from the someplace on the external
side of your firewall, then the port forwarding is working ok.
try manually (using telnet) sending an email thru a connection being
portfw'ed to your qmail server.
-----Original Message-----
From: Michael Hudin [mailto:hudin@zoetrope.com]
Sent: Wednesday, June 05, 2002 11:59 AM
To: netfilter@lists.samba.org
Subject: Re: Outgoing SMTP Mystery
Yeah, I was assuming that there were no default drop rules. I'll make
sure
to implement those.
I did realize that my /etc/hosts file was still set to the old subnet.
I
corrected that, but it still is having the same problem. The gateway on
the
mail machine is set correctly and remember that I can POP in and out and
SMTP out. I just can't get SMTP in for some mind boggling reason.
-michael
----- Original Message -----
From: "Antony Stone" <Antony@Soft-Solutions.co.uk>
To: <netfilter@lists.samba.org>
Sent: Tuesday, June 04, 2002 4:46 PM
Subject: Re: Outgoing SMTP Mystery
> On Tuesday 04 June 2002 11:18 pm, Michael Hudin wrote:
>
> > I've always assumed that the numbers in the brackets were port
allowances
>
> No, they're not (although I can't say what they are - I don't use
> iptables-save). If you look at the numbers, many of them are larger
than
> 65535, so they're certainly not port numbers :-)
>
> > Here are my tables:
> >
> > *nat
> >
> > :PREROUTING ACCEPT [241:88600]
> > :POSTROUTING ACCEPT [0:9862]
> > :OUTPUT ACCEPT [68:4275]
> >
> > *mangle
> >
> > :PREROUTING ACCEPT [18365:3221456]
> > :INPUT ACCEPT [10886:760348]
> > :FORWARD ACCEPT [7269:2438049]
> > :OUTPUT ACCEPT [8009:752540]
> > :POSTROUTING ACCEPT [15177:3182145]
> >
> > *filter
> >
> > :INPUT ACCEPT [0:229546]
> > :FORWARD ACCEPT [363:1553786]
> > :OUTPUT ACCEPT [2:619341]
>
> I find this interesting - you have a default ACCEPT policy on all your
chains
> - specifically on FORWARD, and I cannot see any rules you have
included
which
> DROP or REJECT packets..... so is there really any filtering going on
in
your
> firewall, or is it in fact just an open router doing some network
address
> translation !?
>
> I know this doesn't exactly solve your problem, but I wonder if it
means
the
> problem isn't on your firewall ?
>
> Perhaps you could check the routing table on your SMTP server - what
does
it
> have for a default gateway address ?
>
>
> Antony.
>
>
>
next parent reply other threads:[~2002-06-05 18:21 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <3A5DC36EC1506C40825C05BE65E62AEF0E79EC@neptuno.idea.com.mx>
2002-06-05 18:21 ` Michael Hudin [this message]
2002-06-04 22:18 Outgoing SMTP Mystery Michael Hudin
2002-06-04 22:37 ` Antony Stone
2002-06-04 22:59 ` Travis Crook
2002-06-04 23:28 ` Michael Hudin
2002-06-04 23:46 ` Antony Stone
2002-06-05 17:58 ` Michael Hudin
2002-06-05 17:58 ` patrick conlin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='003a01c20cbd$c3ca9120$5227a8c0@michael' \
--to=hudin@zoetrope.com \
--cc=netfilter@lists.samba.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.