On 27 jan 2015, at 17:24, Tom Eastep <[email protected]> wrote:
> 
> The conntrack table looks very odd. Here's the last entry:
> 
> tcp      6 372883 ESTABLISHED src=192.168.60.2 dst=ho.m.e.ip sport=993
> dport=64604 packets=4 bytes=6000 [UNREPLIED] src=ho.m.e.ip
> dst=pu.bl.ic.ip sport=64604 dport=993 packets=0 bytes=0 mark=0 secmark=0
> use=1
> 
> Although the connection was originally established by ho.m.e.ip
> connecting to pu.bl.ic.ip:993, the left side of the entry has the
> reverse. This indicates that the entry was created by *outgoing* traffic
> rather than incoming traffic. It appears that all of the DNAT
> connections from ho.m.e.ip share this property.
> 
> This looks like an old box (it's running a 2.6 kernel and Shorewall
> 4.4.x) so I assume that this slowness is recent behavior?

Yes, can’t really tell when it started, but it became more obvious when the 
imap server was getting slower and slower. I spent a couple of days upgrading 
and tweaking before I realized that it was the actual network and not the 
service itself.


regards,
Robin
------------------------------------------------------------------------------
Dive into the World of Parallel Programming. The Go Parallel Website,
sponsored by Intel and developed in partnership with Slashdot Media, is your
hub for all things parallel software development, from weekly thought
leadership blogs to news, videos, case studies, tutorials and more. Take a
look and join the conversation now. http://goparallel.sourceforge.net/
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to