Firewall Wizards mailing list archives

RE: POP3 and SMTP slow on Linux since we installed a PIX


From: sean.kelly () lanston com
Date: Mon, 16 Aug 1999 11:22:00 -0400

From: Robert Graham [mailto:robert_david_graham () yahoo com]

It is because you are blocking incoming 113/identd.

When contacted, the e-mail server first opens up a reverse 
connect to identd in
order to log that information. It must first wait for the 
connection to time
out before it continues. Annoying, isn't it?

With many products (web servers for example), reverse name resolution can be
turned off, I assume this isn't the case with mail.  Is this because it
might otherwise log a spoofed ip as the ip of the sender, and the reverse
lookup is some measure of protection against this?  What if mail is
forwarded from a host for which reverse dns fails?

Sean



Current thread: