/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Hi Fuzzy,

Sorry for long delay. I was very busy yesterday. Can I spend some more
of your time on the subj?

FF> This is not strange behavior; this is how ICQ behaves, and why it
FF> requires a protocol module, or port-forwarding, in order to work
FF> properly.

I understand this partially.

FF> All ICQ clients have the ability to send and receive messages via UDP
FF> through the ICQ servers.  However, ICQ recognizes that if everyone did
FF> this, it would not only be a loss of privacy, but also a huge load on
FF> their servers.  So, all ICQ clients will first attempt to send the
FF> message directly to the other ICQ client, via TCP, and only fall back to
FF> sending through the server if the TCP connection fails.

This is fine. And I also see such behavior.

FF> The ICQ client chooses a random port number, and tells the ICQ server
FF> about it.  Other ICQ clients learn about this port number and attempt a
FF> connection directly to it, but when you are masquerading the client,
FF> they attempt to connect to the masq box, and fail.

I also know this.

FF> When your masq'd ICQ client is the first to attempt to send a message,
FF> the outgoing TCP connection is masqueraded, and works fine, assuming
FF> that no firewall stands in the way of getting to the remote ICQ client.
FF> Once that TCP connection is established, communication will proceed
FF> without problems between the two clients.

FF> If the outside ICQ client is the first to attempt to send, it will fail
FF> trying to connect to your masq box, and so the first message will go
FF> through the server via UDP.  Then, when the inside ICQ client responds,
FF> it will set up a TCP connection outbound, and things should still work.

FF> The problem, which you are probably running into, is that there are two
FF> firewalls in place, and neither ICQ client can successfully initiate a
FF> TCP connection to the other.  Thus they both waste time trying.

This is the very interesting part.

Let's consider the situation. One of my internal LAN clients
successfully establishes a TCP connection with his recipient. I can see
it at the MASQ table and time to expire only starts to countdown (say,
it it 14:55.00 now). All fine.

When this connection established I saw 4 packets at my log, as I
mentioned in my previous message. The same client sends second message
to the same recipient within 20-30 seconds from the first one. But
this time I don't see that timer updated and I see againg 4 packets at
my log.

Why is the such pattern observed?

Thanks for your time.


Best regards,
 Dmitriy                            mailto:[EMAIL PROTECTED]

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to