Re: Help Please - DNS issue?

From: Johnson (anonymous_at_discussions.microsoft.com)
Date: 07/16/04


Date: Fri, 16 Jul 2004 12:46:58 -0700

Thanks for the feedback (ext IP still the same), good
point about the banner, I will check that and post a reply
here, I would also like to ask your permission to e-mail
you directly.

Thanks for now
>-----Original Message-----
>> I have a firewall - one to one NAT turned on pointing to
>> my internal Exchange server, reverse DNS works.
>
>Ok, so if I got it right the config should be ...
>
>mailserver <---> nat <----> internet
>
>with a port forward on NAT to allow port
>25 to be published on the 'net
>
>> I installed SPAM filter, changed the NAT to point to
>> SPAM filter, then route port 25 to Exchange server.
>
>Ok, this means
>
>mailserver <--> spamfilter<->nat <--> internet
>
>and I assume that the external (public) address
>wasn't changed i.e. what the internet sees is the
>same IP address as before
>
>> Now the reverse DNS doesn't work. (according to AOL)
>>
>> The FQDN is still the same, MX record is still the same,
>> the only change is the machine name (Exchange server
>> is "LD1", SPAM filter is "mail") and the internal IP,
>> which should not make any difference.
>
>Hmmm ... I wonder if the problem may be caused from the
>"HELO" answer, that is, with the previous configuration
the
>mailserver banner was probably "ld1.yourdomain.com"
>while now it may be "mail.yourdomain.com" this in turn
>means that if an external mailserver checks to see if your
>mailserver answers with the same name registered in the
>DNS this check will fail; imho a solution may be setting
up
>the spam filter so that its banner will be the same as
before
>i.e. "ld1..." this way your problem should be fixed
>
>Let me/us (the newsgroup) know please
>
>
>
>.
>



Relevant Pages

  • Re: SMTP connector not responding
    ... Reverse DNS option is off and even if we wait a long time it just jumps out ... telnet (no banner). ... The netstat command gives a SMTP "listening" port. ...
    (microsoft.public.exchange.admin)
  • Re: dodging SSH-bullets?
    ... telnet to your SSH server port and you'll see what I mean. ... This means that the likelihood of them locating an open port ... signature (specific banner strings, version numbers etc). ...
    (comp.os.linux.security)
  • port scanner
    ... This is my first networking perl program, it is a basic port scanner ... The program exits when the port banner be grab sends a eof. ... Timeout => '1' ... Errmode => 'reture' ...
    (perl.beginners)
  • Re: freesshd 1.0.9 massr00ter
    ... sub banner { ... "Connect over Telnet on Port 1977\n"; ... Pass a Net Neutrality Law in the US!!!! ...
    (alt.computer.security)
  • Re: Incoming SMTP problems
    ... your smtp server doesn't appear to be displaying the banner. ... MCSE, MCT ... >> A quick port check at Shieldsup tells me port 35 is open and netstat ...
    (microsoft.public.exchange.connectivity)