Portál AbcLinuxu, 12. května 2025 09:29
May 30 08:54:48 sysel postfix/smtp[6613]: 099CA80A52: to=xxx.xxx@xxx.sk, relay=xxx.xxx.sk[213.81.132.178]:25, delay=1705, delays=1460/0.07/2.5/243, dsn=4.4.2, status=deferred (conversation with xx.xx.sk[xxx.xxx.xxx.xxx] timed out while sending message body)Nektere emaily (odeslane z Outlook klienta) proste nikdy nedorazi. Prumerna velikost emaily je 1MB. Uz sem zkousel zvednout dvojnasobne hodnoty nasledujich parametru:
smtp_data_done_timeout smtp_data_xfer_timeout smtp_data_init_timeoutbezvysledne. Cilovy postovni server je Lotus Domino Release 8.5.2. Budu vdecny za jakoukoliv radu.
iptables -F INPUT iptables -F OUTPUT iptables -F FORWARD iptables -P INPUT DROP iptables -P OUTPUT ACCEPT iptables -P FORWARD DROP for port in 22332 ftp ftp-data 25 993 990 http https ; do iptables -A INPUT -i eth0 -p tcp --dport $port -j ACCEPT done iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT iptables -A INPUT -p tcp ! --syn -m state --state NEW -j DROP iptables -A INPUT -p tcp -j LOG --log-prefix "~~~~~FIREWALL~~~~~"Tak se komunikace s danym serverem dostane prave az k pravidlu "~~~~~~FIRWALL~~~~~" Viz. vypis ze syslogu
Jun 14 08:03:02 sysel kernel: [322603.633710] ~~~~~FIREWALL~~~~~IN=eth0 OUT= MAC=00:50:56:8f:74:6d:00:21:59:4e:66:c7:08:00 SRC=xxx.xxx.xxx.xxx DST=yyy.yyy.yyy.yyy LEN=52 TOS=0x00 PREC=0x00 TTL=119 ID=18217 DF PROTO=TCP SPT=25 DPT=51811 WINDOW=64240 RES=0x00 ACK FIN URGP=0Nevite proc ?
DROP icmp -f eth0 * 0.0.0.0/0 0.0.0.0/0 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 0 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 4 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 8 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 11 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 0 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 1 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 2 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 3 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 4 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 9 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 10 ACCEPT icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0 icmp type 3 code 13 DROP icmp -- eth0 * 0.0.0.0/0 0.0.0.0/0
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
http://en.wikipedia.org/wiki/Path_MTU_DiscoveryTohle by mohlo pomoci:
iptables -t mangle -A POSTROUTING -p tcp --tcp-flags SYN,RST SYN -o eth0 -j TCPMSS --clamp-mss-to-pmtu
iptables -A INPUT -p tcp -s IP_CILOVEHO_POST_SERVERU -j ACEPT
vse projde jak ma.
iptables -A INPUT -i eth0 -p icmp --icmp-type fragmentation-needed -j ACCEPT
Tiskni
Sdílej:
ISSN 1214-1267, (c) 1999-2007 Stickfish s.r.o.