LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #4  
Old 29-Jun-2009, 12:23 PM
Senior Member
 
Join Date: Aug 2008
Posts: 1,634
phxazcraig 0 reputation points
Default Re: DR BorderManager

OK, I just reread the original thread, and it looks clearly like a
filtering issue. You mentioned that dropping the filters got GWIA
working. So... Something went wrong in the migration of filters from
old to new box. (Filter debug will help a lot in these cases).

For static NAT to an internal GWIA, smtp needs at least two stateful,
or four non-stateful, exceptions for port 25. I prefer the two pairs
of non-stateful myself.

For inbound SMTP from internet to GWIA:
-public to private, tcp dest. Port 25 to GWIA private IP address
-private to public, tcp source port 25 (with ack bit enabled) from GWIA
private IP address.

For outbound SMTP from GWIA to internet, the above, but everything
reversed. (Private to public, tcp dest. Port 25, source ip = GWIA
private address.)

What had me thinking about the secondaries was that you said proxy
worked, and telneting out on port 25 also worked. That told me that
dynamic nat worked, default route was OK, and at least some filter
exceptions were ok. Which suggested to me that static nat was failing
to work. A common cause of static nat failures is not having the
secondary public addresses actually bound. Always check with Display
Secondary Ipaddress to make sure they are there.

I've sometimes (rarely) seen arp tables that did not update on the
internet router side to pick up the new nic change for the addresses.

Craig Johnson
Novell Support Connection SysOp
*** For a current patch list, tips, handy files and books on
BorderManager, go to http://www.craigjconsulting.com ***


Reply With Quote
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -6. The time now is 03:48 AM.


© 2007 Novell, Inc. All Rights Reserved.

Search Engine Friendly URLs by vBSEO 3.3.0 RC2