OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
RE: Problem 500_non-rfc compliant error from PIX to Postfix

From: Gary V (mr88talenthotmail.com)
Date: Wed Apr 02 2008 - 15:59:43 CDT


> Mike Abraham:
>> Mike Abraham:
>>> Thank you for the response.
>>>
>>> While this does describe the result, it is not the cause. I have
>>> come across this page several times.
>>>
>>> It seems to be caused by the PIX firewall.
>>>
>>> As soon as they turn off SMTP FIXUP PROTOCOL, it starts working fine.
>>>
>>> I can't seem to convince everyone to turn off the FIXUP MAILGUARD
>>> function, so I need a Postfix workaround.
>>
>>> The workaround depends on which SMTP command gets screwed up.
>>> Postfix gives some hints in the maillog file.
>>
>> Wietse
>>>>> On 4/2/2008 at 2:19 PM, Wietse Venema wrote:
>>
>> The problem is, my DEBUG_PEER log shows the session is suddenly dropped by the sender.
>>
>>> unknown[209.128.19.200]: 220 watson.conestogac.on.ca ESMTP Postfix ready
>> < unknown[209.128.19.200]: EHLO EXCHANGE.Bluedrop.local
>>> unknown[209.128.19.200]: 250-watson.conestogac.on.ca
>>> unknown[209.128.19.200]: 250-PIPELINING
>>> unknown[209.128.19.200]: 250-SIZE 30720000
>>> unknown[209.128.19.200]: 250-VRFY
>>> unknown[209.128.19.200]: 250-ETRN
>>> unknown[209.128.19.200]: 250 8BITMIME
>> < unknown[209.128.19.200]: QUIT <<< SUDDENLY DROPS SESSION ?
>>> unknown[209.128.19.200]: 221 Bye
>
> What does this have to do with SMTP FIXUP PROTOCOL? If Postfix is
> receiving mail through a firewall with SMTP FIXUP turned on, then
> there is no way that Postfix "work around" the damage that FIXUP
> does.
>
> Wietse

Just guessing, but maybe the client does not like the 8BITMIME ehlo keyword

http://www.postfix.org/postconf.5.html#smtpd_discard_ehlo_keyword_address_maps

Gary V

_________________________________________________________________
Get in touch in an instant. Get Windows Live Messenger now.
http://www.windowslive.com/messenger/overview.html?ocid=TXT_TAGLM_WL_Refresh_getintouch_042008