/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Can anybody point me in the right direction?

Have recently switched our LAN connection to internet from built-in
firewalling ISDN router to a non-firewalling ADSL modem with a linux
firewall box setup to block certain traffic to internal mail and web server.

The problem is that some e-mail from the internet is not making it through
to the mail server.  It seems sporadic.  Internet e-mail from certain
domains to our domain is getting returned with errors varying from "host not
found" to "message had fatal transmission errors".  All web traffic to the
internal web server makes it through fine.  Sometimes, e-mail from one
domain gets delivered with a long delay (days) then all the mail arrives at
once.  All internal to internet mail makes it out fine - pronto.

Here are the knowns:

1.  The mail server (linuxppc sendmail 8.9.3 / 2.2.6 kernel) configuration
   has not changed.  It worked before.  It should work now.

2.  My ISP is the authoratative host for our domain name.  During the switch
   over to ADSL - we were given a different static ip, I had them update
   the mapping of our MX records to the new static ip.  I initially thought
   this might be a problem with caching nameservers on the internet not
   updating their caches.  However, this has now been going on for over two
   weeks.

3.  The linux firewall (ipchains) is set to allow ICMP messages back to
   internet senders so error messages should make it back to the sender.

4.  I've checked the message logs on the firewall machine and there are no
   errors or packets denied.  If there were a mail transmission error, the
   logs should pick it up.  nothing.

5.  I've checked the sendmail logs on the mail server and there are no mail
   errors (except for the odd "queue-could not re-write map junk" which has
   nothing to do with this problem I don't think).

I am baffled.  It almost seems like the traffic isn't even making it from
the adsl modem to the linux firewall box.  If it did, it should be logged.
Any ideas would be appreciated.  I've read everything from possible packet
fragmentation bugs in the kernal to incorrect firewalling rulesets for
ipchains.  At the very least, I should see errors or packets denied in my
logs.  nothing.

Any ideas would be appreciatted.

Sincerly,
graham 

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to