> That looks wrong. Where is the first EHLO response line? The above 
    > starts in the middle of the response.
    >
    > Can you share a packed dump OFF-LIST so I can see what happens between
    > SENDING ehlo and receiving the reply? The entire TCP connection would 
    > be best.
    
Yes, I extracted only the interesting part. The full dump is here (server with 
IP X.X.X.X is mine. Server with IP Y.Y.Y.Y is remote MX):

1   0.000000 X.X.X.X -> Y.Y.Y.Y TCP 74 64550 → 25 [SYN] Seq=0 Win=29200 Len=0 
MSS=1460 SACK_PERM=1 TSval=1363265141 TSecr=0 WS=128

0000  00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00   .PV.0X.PV.d...E.
0010  00 3c 76 fb 40 00 40 06 9a fb ac 11 19 23 d5 29   .<v.@.@......#.)
0020  8e 67 fc 26 00 19 8b 00 b0 8e 00 00 00 00 a0 02   .g.&............
0030  72 10 28 f4 00 00 02 04 05 b4 04 02 08 0a 51 41   r.(...........QA
0040  c6 75 00 00 00 00 01 03 03 07                     .u........

  2   0.030649 Y.Y.Y.Y -> X.X.X.X TCP 74 25 → 64550 [SYN, ACK] Seq=0 Ack=1 
Win=65535 Len=0 MSS=1300 WS=64 SACK_PERM=1 TSval=2347446220 TSecr=1363265141

0000  00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00   .PV.d..PV.0X..E.
0010  00 3c 1e d3 40 00 37 06 fc 23 d5 29 8e 67 ac 11   .<[email protected]..#.).g..
0020  19 23 00 19 fc 26 f3 55 0e 44 8b 00 b0 8f a0 12   .#...&.U.D......
0030  ff ff 12 f3 00 00 02 04 05 14 01 03 03 06 04 02   ................
0040  08 0a 8b eb 2f cc 51 41 c6 75                     ..../.QA.u

  3   0.030695 X.X.X.X -> Y.Y.Y.Y TCP 66 64550 → 25 [ACK] Seq=1 Ack=1 Win=29312 
Len=0 TSval=1363265148 TSecr=2347446220

0000  00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00   .PV.0X.PV.d...E.
0010  00 34 76 fc 40 00 40 06 9b 02 ac 11 19 23 d5 29   .4v.@.@......#.)
0020  8e 67 fc 26 00 19 8b 00 b0 8f f3 55 0e 45 80 10   .g.&.......U.E..
0030  00 e5 28 ec 00 00 01 01 08 0a 51 41 c6 7c 8b eb   ..(.......QA.|..
0040  2f cc                                             /.

  4   0.063290 Y.Y.Y.Y -> X.X.X.X SMTP 84 S: 220 SMTP Welcome

0000  00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00   .PV.d..PV.0X..E.
0010  00 46 1e d7 40 00 37 06 fc 15 d5 29 8e 67 ac 11   [email protected]....).g..
0020  19 23 00 19 fc 26 f3 55 0e 45 8b 00 b0 8f 80 18   .#...&.U.E......
0030  04 02 cf 47 00 00 01 01 08 0a 8b eb 2f ed 51 41   ...G......../.QA
0040  c6 7c 32 32 30 20 53 4d 54 50 20 57 65 6c 63 6f   .|220 SMTP Welco
0050  6d 65 0d 0a                                       me..

  5   0.063310 X.X.X.X -> Y.Y.Y.Y TCP 66 64550 → 25 [ACK] Seq=1 Ack=19 
Win=29312 Len=0 TSval=1363265156 TSecr=2347446253

0000  00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00   .PV.0X.PV.d...E.
0010  00 34 76 fd 40 00 40 06 9b 01 ac 11 19 23 d5 29   .4v.@.@......#.)
0020  8e 67 fc 26 00 19 8b 00 b0 8f f3 55 0e 57 80 10   .g.&.......U.W..
0030  00 e5 28 ec 00 00 01 01 08 0a 51 41 c6 84 8b eb   ..(.......QA....
0040  2f ed                                             /.

  6   0.063357 X.X.X.X -> Y.Y.Y.Y SMTP 102 C: EHLO mx02-out.cloud.vadesecure.com

0000  00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00   .PV.0X.PV.d...E.
0010  00 58 76 fe 40 00 40 06 9a dc ac 11 19 23 d5 29   .Xv.@.@......#.)
0020  8e 67 fc 26 00 19 8b 00 b0 8f f3 55 0e 57 80 18   .g.&.......U.W..
0030  00 e5 29 10 00 00 01 01 08 0a 51 41 c6 84 8b eb   ..).......QA....
0040  2f ed XX XX XX XX 20 XX XX XX XX 2d XX XX XX 2e   /.EHLO xxxx-xxx.
0050  XX XX XX XX XX 2e XX XX XX XX XX XX XX XX XX XX   xxxxx.xxxxxxxxxx
0060  2e 63 6f 6d 0d 0a                                 .com..

  7   0.096519 Y.Y.Y.Y -> X.X.X.X SMTP 156 S: 250 SIZE 12582912 | 250 DSN | 250 
ENHANCEDSTATUSCODES | 250 AUTH NTLM | 250 8BITMIME | 250 OK

0000  00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00   .PV.d..PV.0X..E.
0010  00 8e 1e da 40 00 37 06 fb ca d5 29 8e 67 ac 11   [email protected]....).g..
0020  19 23 00 19 fc 26 f3 55 0e 57 8b 00 b0 b3 80 18   .#...&.U.W......
0030  04 02 25 56 00 00 01 01 08 0a 8b eb 30 0d 51 41   ..%V........0.QA
0040  c6 84 32 35 30 2d 53 49 5a 45 20 31 32 35 38 32   ..250-SIZE 12582
0050  39 31 32 0d 0a 32 35 30 2d 44 53 4e 0d 0a 32 35   912..250-DSN..25
0060  30 2d 45 4e 48 41 4e 43 45 44 53 54 41 54 55 53   0-ENHANCEDSTATUS
0070  43 4f 44 45 53 0d 0a 32 35 30 2d 41 55 54 48 20   CODES..250-AUTH
0080  4e 54 4c 4d 0d 0a 32 35 30 2d 38 42 49 54 4d 49   NTLM..250-8BITMI
0090  4d 45 0d 0a 32 35 30 20 4f 4b 0d 0a               ME..250 OK..

  8   0.096737 X.X.X.X -> Y.Y.Y.Y SMTP 103 C: MAIL 
FROM:<[email protected]>

0000  00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00   .PV.0X.PV.d...E.
0010  00 59 76 ff 40 00 40 06 9a da ac 11 19 23 d5 29   .Yv.@.@......#.)
0020  8e 67 fc 26 00 19 8b 00 b0 b3 f3 55 0e b1 80 18   .g.&.......U....
0030  00 e5 29 11 00 00 01 01 08 0a 51 41 c6 8d 8b eb   ..).......QA....
0040  30 0d 4d 41 49 4c 20 46 52 4f 4d 3a 3c XX XX XX   0.MAIL FROM:<xxx
0050  XX XX XX XX XX 2e XX XX XX XX 40 XX XX XX XX XX   xxxxx.xxxx@xxxxx
0060  2e 63 6f 6d 3e 0d 0a                              .com>..

  9   0.128714 Y.Y.Y.Y -> X.X.X.X SMTP 87 S: 250 2.1.0 Sender OK

0000  00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00   .PV.d..PV.0X..E.
0010  00 49 1e df 40 00 37 06 fc 0a d5 29 8e 67 ac 11   [email protected]....).g..
0020  19 23 00 19 fc 26 f3 55 0e b1 8b 00 b0 d8 80 18   .#...&.U........
0030  04 02 a9 65 00 00 01 01 08 0a 8b eb 30 2e 51 41   ...e........0.QA
0040  c6 8d 32 35 30 20 32 2e 31 2e 30 20 53 65 6e 64   ..250 2.1.0 Send
0050  65 72 20 4f 4b 0d 0a                              er OK..

 10   0.128822 X.X.X.X -> Y.Y.Y.Y SMTP 140 C: RCPT 
TO:<[email protected]> ORCPT=rfc822;[email protected]

0000  00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00   .PV.0X.PV.d...E.
0010  00 7e 77 00 40 00 40 06 9a b4 ac 11 19 23 d5 29   .~w.@.@......#.)
0020  8e 67 fc 26 00 19 8b 00 b0 d8 f3 55 0e c6 80 18   .g.&.......U....
0030  00 e5 29 36 00 00 01 01 08 0a 51 41 c6 95 8b eb   ..)6......QA....
0040  30 2e 52 43 50 54 20 54 4f 3a 3c XX 2e XX XX XX   0.RCPT TO:<x.xxx
0050  XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX XX   xx@xxxxxxxxxxxxx
0060  2e 66 72 3e 20 4f 52 43 50 54 3d 72 66 63 38 32   .fr> ORCPT=rfc82
0070  32 3b XX XX XX XX XX XX XX 40 XX XX XX XX XX XX   2;xxxxxx@xxxxxxx
0080  XX XX XX XX XX XX XX 2e 66 72 0d 0a               xxxxxxx.fr..

 11   0.164675 Y.Y.Y.Y -> X.X.X.X SMTP 90 S: 250 2.1.5 Recipient OK

0000  00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00   .PV.d..PV.0X..E.
0010  00 4c 1e e2 40 00 37 06 fc 04 d5 29 8e 67 ac 11   [email protected]....).g..
0020  19 23 00 19 fc 26 f3 55 0e c6 8b 00 b1 22 80 18   .#...&.U....."..
0030  04 02 e4 53 00 00 01 01 08 0a 8b eb 30 52 51 41   ...S........0RQA
0040  c6 95 32 35 30 20 32 2e 31 2e 35 20 52 65 63 69   ..250 2.1.5 Reci
0050  70 69 65 6e 74 20 4f 4b 0d 0a                     pient OK..

 12   0.164764 X.X.X.X -> Y.Y.Y.Y SMTP 72 C: DATA

0000  00 50 56 9b 30 58 00 50 56 9b 64 b4 08 00 45 00   .PV.0X.PV.d...E.
0010  00 3a 77 01 40 00 40 06 9a f7 ac 11 19 23 d5 29   .:w.@.@......#.)
0020  8e 67 fc 26 00 19 8b 00 b1 22 f3 55 0e de 80 18   .g.&.....".U....
0030  00 e5 28 f2 00 00 01 01 08 0a 51 41 c6 9e 8b eb   ..(.......QA....
0040  30 52 44 41 54 41 0d 0a                           0RDATA..

 13   0.197068 Y.Y.Y.Y -> X.X.X.X SMTP 112 S: 354 Start mail input; end with 
<CRLF>.<CRLF>

0000  00 50 56 9b 64 b4 00 50 56 9b 30 58 08 00 45 00   .PV.d..PV.0X..E.
0010  00 62 1e ee 40 00 37 06 fb e2 d5 29 8e 67 ac 11   [email protected]....).g..
0020  19 23 00 19 fc 26 f3 55 0e de 8b 00 b1 28 80 18   .#...&.U.....(..
0030  04 02 0f 11 00 00 01 01 08 0a 8b eb 30 72 51 41   ............0rQA
0040  c6 9e 33 35 34 20 53 74 61 72 74 20 6d 61 69 6c   ..354 Start mail
0050  20 69 6e 70 75 74 3b 20 65 6e 64 20 77 69 74 68    input; end with
0060  20 3c 43 52 4c 46 3e 2e 3c 43 52 4c 46 3e 0d 0a    <CRLF>.<CRLF>..


(more than 10k paquets of data…)

10640  15.358175 X.X.X.X -> Y.Y.Y.Y SMTP 2642 C: DATA fragment, 2576 bytes
10641  15.362672 Y.Y.Y.Y -> X.X.X.X TCP 66 25 → 64550 [ACK] Seq=200 
Ack=12584250 Win=95872 Len=0 TSval=2347461552 TSecr=1363268963
10642  15.362688 X.X.X.X -> Y.Y.Y.Y SMTP 2642 C: DATA fragment, 2576 bytes
10643  15.363923 Y.Y.Y.Y -> X.X.X.X SMTP 90 S: 552 Data size exceeded
10644  15.363938 X.X.X.X -> Y.Y.Y.Y SMTP 1354 C: DATA fragment, 1288 bytes
10645  15.519580 X.X.X.X -> Y.Y.Y.Y SMTP 1354 C: DATA fragment, 1288 bytes
10646  15.799532 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25 
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363269091 TSecr=2347461552
10647  16.351553 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25 
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363269229 TSecr=2347461552
10648  17.459539 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25 
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363269506 TSecr=2347461552
10649  19.679610 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25 
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363270061 TSecr=2347461552
10650  24.107530 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25 
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363271168 TSecr=2347461552
10651  32.971650 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25 
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363273384 TSecr=2347461552
10652  50.667578 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25 
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363277808 TSecr=2347461552
10653  86.059559 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25 
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363286656 TSecr=2347461552
10654 156.971556 X.X.X.X -> Y.Y.Y.Y TCP 1354 [TCP Retransmission] 64550 → 25 
[ACK] Seq=12584250 Ack=224 Win=29312 Len=1288 TSval=1363304384 TSecr=2347461552
10655 195.472753 X.X.X.X -> Y.Y.Y.Y 64550 → 25 [RST, ACK] Seq=12656378 Ack=224 
Win=29312 Len=0 TSval=1363314009 TSecr=2347461552


Reply via email to