OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: RE:^A^A^H junk -> Bad device found :-)
From: Gerald Richter (richterecos.de)
Date: Sun Mar 26 2000 - 06:55:04 CST


>
> I have stopped tcpdump at 17:15 UTC-0500, and have started a new
> tcpdump to record SMTP sessions with merkur.ecos.de.
>
> > So if you still like to capture the tcpstream, please change the host to
> > merkur.ecos.de. (Also I think it isn't really neccessary,
> because if there
> > are any errors, I see it anyway in the logs)
>
> The ISP's bridge normally rewrites every TCP packet. If it's made
> transparent, then your tcpdumped packets should be the same as
> mine, except for trivial differences such as the TTL field.
>

We have made the following test:

I send a mail every minute from the internet to merkur.ecos.de and also one
mail from merkur.ecos.de to spike.procupine.org. We have switched the bridge
at our ISP to just forward every traffic from/to merkur.ecos.de. In this
setup I didn't have got any errors for 24 hours. After this, we switch back
the bridge to normal traffic shaping mode and as soon as this is done the
errors starts again. So we can be very sure that we have found the
problematic device. The bridge is a realtime linux based bandwidth
management system. Our ISP will now talk to their distributor to solve the
problem.

The isolation of this problem and the problematic device, was only possible
due to the much help on this list and the excellent interpretation of the
tcp communication by Wieste. Very much thanks! Just one more reason to use
Postfix :-)

Gerald

-------------------------------------------------------------
Gerald Richter ecos electronic communication services gmbh
Internetconnect * Webserver/-design/-datenbanken * Consulting

Post: Tulpenstrasse 5 D-55276 Dienheim b. Mainz
E-Mail: richterecos.de Voice: +49 6133 925151
WWW: http://www.ecos.de Fax: +49 6133 925152
-------------------------------------------------------------