/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Can anybody point me in the right direction? Have recently switched our LAN connection to internet from built-in firewalling ISDN router to a non-firewalling ADSL modem with a linux firewall box setup to block certain traffic to internal mail and web server. The problem is that some e-mail from the internet is not making it through to the mail server. It seems sporadic. Internet e-mail from certain domains to our domain is getting returned with errors varying from "host not found" to "message had fatal transmission errors". All web traffic to the internal web server makes it through fine. Sometimes, e-mail from one domain gets delivered with a long delay (days) then all the mail arrives at once. All internal to internet mail makes it out fine - pronto. Here are the knowns: 1. The mail server (linuxppc sendmail 8.9.3 / 2.2.6 kernel) configuration has not changed. It worked before. It should work now. 2. My ISP is the authoratative host for our domain name. During the switch over to ADSL - we were given a different static ip, I had them update the mapping of our MX records to the new static ip. I initially thought this might be a problem with caching nameservers on the internet not updating their caches. However, this has now been going on for over two weeks. 3. The linux firewall (ipchains) is set to allow ICMP messages back to internet senders so error messages should make it back to the sender. 4. I've checked the message logs on the firewall machine and there are no errors or packets denied. If there were a mail transmission error, the logs should pick it up. nothing. 5. I've checked the sendmail logs on the mail server and there are no mail errors (except for the odd "queue-could not re-write map junk" which has nothing to do with this problem I don't think). I am baffled. It almost seems like the traffic isn't even making it from the adsl modem to the linux firewall box. If it did, it should be logged. Any ideas would be appreciated. I've read everything from possible packet fragmentation bugs in the kernal to incorrect firewalling rulesets for ipchains. At the very least, I should see errors or packets denied in my logs. nothing. Any ideas would be appreciatted. Sincerly, graham _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
