Firewall Wizards mailing list archives

Re: POP3 and SMTP slow on Linux since we installed a PIX


From: Eric Vyncke <evyncke () cisco com>
Date: Sat, 14 Aug 1999 08:40:57 +0200

Dave,

Most of the time, the problem is linked because recent sendmails are, by default,
triggering an IDENT connection to the source of the SMTP session. PIX is
blocking IDENT by default without sending an ICMP message back to the source
(which is a secure behaviour in my biased experience)

You may want to either authorize IDENT through the PIX (bad!) or have the PIX
sends the ICMP message (via a sysopt configuration command).

Hope this helps

-eric

At 16:11 13/08/1999 -0400, Salatino, Dave wrote:
We installed a PIX firewall and ever since POP and SMTP have been slow to
establish a connection to the mail server on the DMZ from the inside. Has
anyone here seen the same symptom?

TIA Dave

Eric Vyncke                        
Consulting Engineer                Cisco Systems EMEA
Phone:  +32-2-778.4677             Fax:    +32-2-778.4300
E-mail: evyncke () cisco com          Mobile: +32-75-312.458



Current thread: