LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 02-09-2005, 09:54 AM   #1
[GOD]Anck
Member
 
Registered: Dec 2003
Location: The Netherlands
Distribution: Slackware
Posts: 171

Rep: Reputation: 31
postfix/smtpd lost connection after CONNECT


I've been going over some Postfix logs lately and I've noticed some stanzas like this:

Code:
Feb  9 15:56:39 linux postfix/smtpd[26348]: connect from FQDN[IP.IP.IP.IP]
Feb  9 15:56:39 linux postfix/smtpd[26348]: lost connection after CONNECT from FQDN[IP.IP.IP.IP]
Feb  9 15:56:39 linux postfix/smtpd[26348]: disconnect from FQDN[IP.IP.IP.IP]
Normally I would probably dismiss them as just failed connection attempts, but there are several of these coming from the same address, and nobody from that address should be sending any e-mail through my Postfix. could this be some kind of automated search for open relays, or some other malware? Google really only leads to threads about Postfix configuration problems where mine works like it should. Any ideas?
 
Old 12-18-2011, 02:10 PM   #2
abarclay
LQ Newbie
 
Registered: Aug 2003
Posts: 22

Rep: Reputation: 3
I have been running my own mail server on postfix for quite a few years. A few months ago, I started having this problem where mail from a specific domain would not be delivered.

I was getting the following error:

Nov 29 15:04:20 woody2 postfix/smtpd[19251]: connect from mail.brent.ca.us[100.199.141.143]
Nov 29 15:04:20 woody2 postfix/smtpd[19251]: lost connection after CONNECT from mail.brent.ca.us[100.199.141.143]

The fact that it was only one domain that was causing this led me to believe that the problem was on the client side, but I did my due diligence to try to fix it including:
1) increasing concurrency in master.cf
2) disabling mailscanner
3) removing sender restrictions
4) disabling grey listing

I called an administrator over at the place and chatted with him for a while. He thought it was on my end, but after I explained what I had tried he did a little investigation and determined that the problem was on his end.

Apparently, they run or subscribe to a "filter" mechanism that fetches the web-pages associated with the destination email domain, and prevents email from being sent to that domain if they find anything there that they don't like.

He said, "There was a filter that found “adult language” within your domain. Your IP has been unblocked."

So, he had to whitelist my IP.

Just wanted to post this solution because it caused me so much grief.

Andy
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
[Postfix/SMTPD] Getting no AUTH from server; open relay superhausi Linux - Security 2 11-19-2008 05:37 PM
Sending mail via Postfix smtpd through remote host requiring authentication Saffsd Linux - Networking 0 01-26-2004 05:05 AM
Smtp vs. Smtpd on Postfix BeerBust Linux - Software 1 10-10-2003 11:07 AM
Lost my instructions for wireless connect...oops! jpohara Linux - Newbie 4 04-24-2002 09:49 PM
connection lost toma Linux - Networking 2 09-07-2001 06:49 AM


All times are GMT -5. The time now is 04:36 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration