Re: lost connection after DATA Q?

2010-05-14 Thread Charles Marcus
On 2010-05-13 9:59 PM, Gary Smith wrote: Anyway, we are still receiving them. The firewall allows port 25 incoming, everything outgoing but there is also some nat'ing going on because of the ipvsadm. Anyone ever seen this type of issue with this type of config? Per the welcome message you

Re: lost connection after DATA Q?

2010-05-14 Thread Wietse Venema
Gary Smith: I've been getting a lost of lost connection after DATA this last week. On our low volume servers (that houses some minor clients) we are receiving 800/day. We switched over to ipvsadm about 3 weeks ago and I though maybe it's because of non-persistent connections. So I reset

RE: lost connection after DATA Q?

2010-05-14 Thread Gary Smith
Per the welcome message you received when you joined the list: That would be like 5+ years ago. I've slept since then. TO REPORT A PROBLEM see: http://www.postfix.org/DEBUG_README.html#mail At a minimum, postfix version, output of postconf -n and unedited NON-verbose logs exhibiting

RE: lost connection after DATA Q?

2010-05-14 Thread Gary Smith
Weitse, For some reason, random mails from you pop up in my inbox, instead of my postfix list instead delivery on behalf of postfix-users@postfix.org like most others. Just an FYI If the NAT assumes that everything is a web client and drops connections after a few seconds, then Postfix

Re: lost connection after DATA Q?

2010-05-14 Thread Victor Duchovni
On Fri, May 14, 2010 at 09:23:12AM -0700, Gary Smith wrote: I'm sure it's not a probable with postfix, I'm just looking for postfix cases where they have overcome this type of config issue. Have you disabled window scaling on your Postfix server. Lost connections are often the result of

RE: lost connection after DATA Q?

2010-05-14 Thread Gary Smith
Have you disabled window scaling on your Postfix server. Lost connections are often the result of firewalls mangling advanced TCP features. - Disable window scaling - Disable ECN I don't believe we have disabled any of the advanced features. That will give me something to do

Re: lost connection after DATA Q?

2010-05-14 Thread Wietse Venema
Gary Smith: If the NAT assumes that everything is a web client and drops connections after a few seconds, then Postfix will report lost connections. If the NAT keeps connections open but it is a crappy box that can maintain state for only 100 connections, then it will be forced to

Re: lost connection after DATA Q?

2010-05-14 Thread Wietse Venema
Gary Smith: May 13 18:48:33 host01 postfix/smtpd[18110]: connect from sender[senderip] May 13 18:48:33 host01 postfix/smtpd[18110]: setting up TLS connection from sender[senderip] May 13 18:48:33 host01 postfix/smtpd[18110]: Anonymous TLS connection established from sender[senderip]: TLSv1

RE: lost connection after DATA Q?

2010-05-14 Thread Gary Smith
This strongly suggests that you have is a 10 second time limit on the life time of NAT/VPS/whatever state. Wietse Makes complete sense. I will bounce it off the ipvsadm list. They don't tend to respond much as of recent. BTW, I did notice, while analyzing some of the logs, that a

Re: lost connection after DATA Q?

2010-05-14 Thread Victor Duchovni
On Fri, May 14, 2010 at 11:20:47AM -0700, Gary Smith wrote: May 13 04:08:33 host01 postfix/smtpd[10912]: lost connection after DATA from unknown[82.178.110.201] Listed on SpamHaus XBL and PBL May 13 04:08:34 host01 postfix/smtpd[10409]: lost connection after RCPT from

RE: lost connection after DATA Q?

2010-05-14 Thread Gary Smith
May 13 04:09:23 host01 postfix/smtpd[10301]: lost connection after RCPT from unknown[190.107.112.194] Listed on SpamHaus XBL Unless these listings postdate your log entries, you should probably not allow these clients to get as far as DATA. reject_rbl_client zen.spamhaus.org

lost connection after DATA Q?

2010-05-13 Thread Gary Smith
I've been getting a lost of lost connection after DATA this last week. On our low volume servers (that houses some minor clients) we are receiving 800/day. We switched over to ipvsadm about 3 weeks ago and I though maybe it's because of non-persistent connections. So I reset ipvsadm to be