[pmmail-list] firewalls

PMMail OS/2 Support pmmail-list@blueprintsoftwareworks.com
Tue, 27 Mar 2001 09:54:32 -0400


On Mon, 26 Mar 2001 19:14:24 -0800, Kenneth Porter wrote:

>However, the typical PC doesn't provide an ident server. What may be
>happening is that the firewall responds to the ident probe differently
>than the un-firewalled PC. For example, the stock PC probably responds
>with an ICMP-unreachable packet. This quickly tells the polling host
>that its attempt is doomed to failure and allows it to proceed
>immediately. The firewall may be just sitting silent, and the polling
>system waits until a timeout for a reply that will never come.
>
>On a Linux host, this behavior can be configured with the ipchains
>firewall by selecting either a policy of "deny" (drop packet silently)
>or "reject" (respond with failure message). Look for something similar
>in your PC firewall.

OK, the pop server does use ident, but this does not fix anything. I
set a rule to allow all ICMP packets incoming or outgoing to any IP
on any port.

The PMMail 2000 delay still occurs with "connecting to pop server"
every time I try with the firewall active. There is no delay without
the firewall running.

Weird.


--
Trevor Smith
PMMail/2 Technical Support
pmmailos2@blueprintsoftwareworks.com



- pmmail-list - The PMMail Dicussion List ---------------------------
To UNSUBSCRIBE, send a message to mdaemon@bmtmicro.com with the first 
line of the message body being...
UNSUBSCRIBE pmmail-list@blueprintsoftwareworks.com