Firewall randomly drops connections

maturos

Member
Apr 26, 2022
30
1
8
Hello, I've a container which needs to send mails to a server located in the internet via SMTP. Default outgoing behaviour is reject.
I started with an outgoing rule using the SMTPS-Macro and restricted the destination ip address. So far, so good; but it didn't work. So I removed the IP address restriction and left the SMTPS macro active. This worked.
So next I added the IPSet for the destination restriction again. Some mails went through, some not. I tried protocol tcp and port 465 as i suspected the SMTPS macro to be broken and after that I ended with this setup:
1704218221308.png
The IPSet "smtp" contains the following addresses in which the smtp server is located:
1704218372582.png
In the attached zip file you'll find four attempts to send e-mails with the rule shown above. The first 3 attempts were successful, the fourth one failed with 3 retransmissions.
The capture filter was 'tcpdump -n -i eth0 dst 81.169.145.133 or dst 2a01:238:20a:202:55f0::1133' for the current ip addresses of the foreign server.

What am i doing wrong here?
 

Attachments

  • truncated_capture.zip
    1.3 KB · Views: 1
Last edited:

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!