Hi,

That makes sence.
And then again not. I have closed for all ident traffic on the firewall 
inbound, but why does it only affect some of my customers ?

And then the stupid question how do I disable ident lookup ?

Thanks,

Thomas

>Greetings,
>This is a known problem when running nat/pat and qmail.  It involves the 
>identd
>packets that the server sends out on port 113.  I noticed these originally 
>when
>my IProute box firewall complained about intrusion attempts on that 
>port.  After
>4 of them, my mail went through.  The easiest way to solve this is use a NAT
>proxy or passthrough to pass port113 on to any internal machine.  The mail 
>server
>will get a connection refused message from the box instead of a timeout.  The
>other solution is to disable identd lookups on the mail server.
>
>--
>------------------------------------------------------------------------
>// Jere Cassidy  -  System Administration - D&E SuperNet
>         email: [EMAIL PROTECTED]    phone: (717)738-7054
>         web: http://www.desupernet.net/jere
>         pager/pcs: [EMAIL PROTECTED] - (717)203-0042
>~~~ "While sowing the seeds of Utopia,
>  you invoked a convenient amnesia" -BR ~~~
>------------------------------------------------------------------------
>
>
>Thomas Balle wrote:
>
> > Hi,
> >
> > For some time I have experienced a problem which may be a qmail problem but
> > Im not sure.
> >
> > I have a number of dial in customers who uses ISDN routers with pat/nat
> > translation some of them have great difficulties sending and checking mail,
> > it often takes in excess of 20 sec. to establish a connection to my qmail
> > server regardless of the client program (I also tried to telnet directly to
> > port 25 and 110 it takes the same time)
> >
> > Other customers with the same/very similar hardware config connects without
> > a problem.
> > I have not experienced the problem with customers who has direct access to
> > the internet ie via a modem dialup.
> >
> > For all I can see the pat/nat works fine and they connect rapidly to all
> > other servers on my network including af test server I have running 
> sendmail.
> >
> > What could make the connect time so extremely slow ?
> >
> > Thanks,
> >
> > Thomas
>

Reply via email to