OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: "Connection refused" not skipped
From: Wietse Venema (wietseporcupine.org)
Date: Mon Feb 21 2000 - 07:24:14 CST


[J_rgen] Fluk:
> Wietse Venema wrote:
> >
> > Evidence from logfiles, please. Postfix logs all IP addresses
> > that it has tried for a domain before giving up.
> >
> > Use: egrep 'mailin.webmailer.de' on your maillog file.
> >
> > Wietse
>
> [Sorry for long lines]

Woud not it be great if people stopped using crappy mail software
that wraps long lines in logfiles.

The logging below does not show IP address information. According
to the Postfix source code, Postfix tries ALL IP addresses for a
host in case of ECONREFUSED.

        Wietse

> Feb 16 18:02:18 midas postfix/smtp[4623]: 12F953ECDD:
> to=<b.awaloff4c-ag.de>,
> relay=mailin.webmailer.de, delay=4, status=sent (250 SAA13725 Message
> accepted for delivery)
> Feb 17 09:12:12 midas postfix/smtp[16074]: D962E3ECDC:
> to=<b.awaloff4c-ag.de>, relay=none, delay=4, status=deferred (connect to
> mailin.webmailer.de: Connection refused)
> Feb 17 09:33:55 midas postfix/smtp[16226]: D962E3ECDC:
> to=<b.awaloff4c-ag.de>, relay=none, delay=1307, status=deferred (connect
> to mailin.webmailer.de: Connection refused)
> Feb 17 10:07:05 midas postfix/smtp[16565]: D962E3ECDC:
> to=<b.awaloff4c-ag.de>, relay=none, delay=3297, status=deferred (connect
> to mailin.webmailer.de: Connection refused)
> Feb 17 11:53:12 midas postfix/smtp[16933]: D962E3ECDC:
> to=<b.awaloff4c-ag.de>, relay=none, delay=9664, status=deferred (connect
> to mailin.webmailer.de: Connection timed out)
> Feb 17 13:36:47 midas postfix/smtp[17657]: D962E3ECDC:
> to=<b.awaloff4c-ag.de>, relay=none, delay=15879, status=deferred (connect
> to mailin.webmailer.de: Connection refused)
> Feb 17 14:50:26 midas postfix/smtp[18121]: D962E3ECDC:
> to=<b.awaloff4c-ag.de>, relay=none, delay=20298, status=deferred (connect
> to mailin.webmailer.de: Connection refused)
> Feb 17 15:57:06 midas postfix/smtp[18469]: D962E3ECDC:
> to=<b.awaloff4c-ag.de>, relay=none, delay=24298, status=deferred (connect
> to mailin.webmailer.de: Connection refused)
> Feb 17 16:10:20 midas postfix/smtp[18566]: 077E41D7EA:
> to=<b.hutzel4c-ag.de>, relay=mailin.webmailer.de, delay=10, status=sent
> (250 QAA18121 Message accepted for delivery)
> Feb 17 17:03:47 midas postfix/smtp[18878]: D962E3ECDC:
> to=<b.awaloff4c-ag.de>, relay=mailin.webmailer.de, delay=28299,
> status=sent (250 RAA26190 Message accepted for delivery)
> F
>
> Am I missing certain log levels, or is my syslog.conf bad? I don't see IP
> numbers (:-).
> I just found that our internal DNS holds a MX record for 4c-ag.de
> (historical reasons)
> which is a CNAME to mailin.webmailer.de; maybe this is the reason?
> louis
>
> > [J_rgen] Fluk:
> > > We are still running 19990601 here (just in train to upgrade).
> ...
> > > E.g. the MX for "4c-ag.de" points to mailin.webmailer.de, and this one has
> > > 3 IPs
> > > Name: mailin.webmailer.de
> > > Addresses: 192.67.198.48, 192.67.198.37, 192.67.198.32
> --
> J_rgen Fluk louisntm-gmbh.de
> New Technologies Management GmbH Tel +49 89 993415-56
> Stefan-George-Ring 24, D-81929 M_nchen Fax +49 89 993411-99
>
>