OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Alex van den Bogaerdt (alex_at_ergens.op.HET.NET)
Date: Fri Jul 26 2002 - 08:16:07 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    mlsveginfo.com wrote:
    >
    > Alex van den Bogaerdt wrote:
    > > Surely if the remote host sends an ack, it will procede by
    > > sending "data" ?
    >
    > One would hope so, but it is not happening.

    As you've already seen on the postfix list, the problem is in
    retransmissions. This means a packet was not acknowledged,
    most likely because it didn't arrive.

    > > Make sure you're capturing on a separate device.
    >
    > Does it make a difference? Currently I do not have that
    > flexibility. Have to do some rewiring, loading software
    > on some computers etc to be able to do that.

    If everything's working as expected: no, you don't need more
    than one capture. However, if it is NOT working as expected
    you want to know where things go wrong.

    In your particular case I expect that ICMP packets are blocked.
    The packet will mean "Fragmentation needed but Don't Fragment bit set".
    When this ICMP-packet doesn't arrive, the host has no way of
    knowing it should lower the segment size for this connection.
    It also doesn't know it should send the same data again.

    Look for "MTU black hole" on the internet.

    cheers,
    Alex
    -
    To unsubscribe, send mail to majordomopostfix.org with content
    (not subject): unsubscribe postfix-users