Re: q CWR ECE SYN

From: RainbowHat (nHiATlE_at_blSackholeP.mAit.edMu.invalid)
Date: 07/15/03


Date: Tue, 15 Jul 2003 19:55:45 +0000 (UTC)


< Jason

>if I telnet that mail server from my Linux box, the packets to that
>server is not SYN, it is CWR ECE SYN. And the remote mail server
>respond with nothing back.

--> Reason
RFC3360 Inappropriate TCP Resets Considered Harmful
3. The Specific Example of ECN
In short, iptables, intermediate gateway or target host drop the
legitimate packets.

--> Troubleshoot
Run `tcpdump` and `hping2` <http://kyuzz.org/antirez/> with SYN|ECE|
CWR TCP flags and traceroute mode.

hping2 -nVTSXYc 32 -p 25 mail.srv.ip.addr

--> Solution
If problem is your own network, re-configure it (Sorry, configuration
is not my business). If not, (e)mail to the owner.

--> Work around (Note: just a work around not a real solution)

echo 0 > /proc/sys/net/ipv4/tcp_ecn

BTW why do you need to send _remote_ mail server (not your ISP?)
_directly_? In most case, spammer is doing (MXware). What's your
purpose?

-- 
"Be liberal in what you accept, and conservative in what you send."
"adaptability to change must be designed into all levels of Internet 
host software" from RFC3360. Hope This Informative, RainbowHat.
----+----1----+----2----+----3----+----4----+----5----+----6----+----7


Relevant Pages

  • Re: Exchange Queue Filling UP - Preventing legitimate mail flow
    ... Spammer spoofs a users email address. ... A vast majority of those spam emails go to blocked, non-existant, or ... Mydomain mail server creates a connection to each remote mail server to ...
    (microsoft.public.exchange.admin)
  • Problem with cluster and multiple IPs
    ... We have an Exchange cluster and on the public interface we have it set for an ... The problem is when a remote mail server wants to do a reverse lookup it ...
    (microsoft.public.exchange.connectivity)
  • Re: Message stuck in queue- why?
    ... You'll need to check DNS, correct MX record lookup from the ... mail server and if you can successfully telnet from your mail server ... to the remote mail server on port 25. ...
    (microsoft.public.exchange.admin)
  • Re: Error #554 5.7.1 - not sure how to approach
    ... is the IP your mail server is truly using when talking to the internet. ... Then work on setting up reverse DNS for this IP and verify it works to the ... and I monitored the smtp queue ... > queued, the connecting with the remote mail server made, ...
    (microsoft.public.exchange2000.general)