- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - Linux
- >
- Re: Reverse Lookup zone benefits ?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2006 06:37 AM
тАО08-08-2006 06:37 AM
I dont know why... but there must be a relation-ship between sendmail and reverse lookup zone, becuase when I dont create the reverse lookup zone, using Outlook Express, send/recieve takes a lot much time, but when I create the reverse lookup zone, send/receive is very fast.
So I wana know why send/receive gets the benefit(in terms of speed) from reverse lookup zone ?
And is there any other benefits of creating reverse lookup zone ?
Regards
Maaz
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2006 06:52 AM
тАО08-08-2006 06:52 AM
SolutionMain benefit is when you send mail to the Internet most mail servers require valid reverse lookup prior to accepting the mail.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2006 07:19 AM
тАО08-08-2006 07:19 AM
Re: Reverse Lookup zone benefits ?
Some services gives you an option to disable the reverse lookup, some other don't.
Is good to have a reverse lookup for these reasons, also it could help you to identify your hosts in your network.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2006 07:45 AM
тАО08-08-2006 07:45 AM
Re: Reverse Lookup zone benefits ?
smtp server: sendmail 8.x
when I dont create the reverse lookup zone, using Outlook Express, send/recieve takes a lot much time, but when I create the reverse lookup zone, send/receive is very fast.
Any Reason ?
Regards
Maaz
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2006 08:20 AM
тАО08-08-2006 08:20 AM
Re: Reverse Lookup zone benefits ?
http://www.sendmail.org/~ca/email/check.html#check_relay
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-08-2006 10:26 AM
тАО08-08-2006 10:26 AM
Re: Reverse Lookup zone benefits ?
That being said, you can get around it by using a properly populated 'hosts' file usually (and a service.switch file).
As Ivan says though, if you're using a pre-compiled package, there's no real way you can get around using it.
All this being said, why aren't you setting up reverse zone files? It's not hard to do, and if it is an internal network, and you don't care what the individual machines reverse lookup returns (sendmail doesn't unless you turn on some pretty harsh options for HELO matching), then simple names are more than enough, i.e.:
1 IN PTR 1.internal.
for all 255 numbers, and you can copy it around *shrug*.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-09-2006 12:31 AM
тАО08-09-2006 12:31 AM
Re: Reverse Lookup zone benefits ?
In your case, there may be an alternate dns server that has reverse zones defined or the applicaiton may simply timeout and either use what it has.
The benefits are that it can greatly increase connection times avoiding long delays. It's up to you to weigh the benefits.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-09-2006 12:38 AM
тАО08-09-2006 12:38 AM
Re: Reverse Lookup zone benefits ?
Answer to your question.
My servers will reject your mail out of hand if there is no reverse lookup zone.
Other servers will drop your priority, making it harder to process your message,introducing delays.
If you do some email interactively with telnet, you will see this yourself. You will also see messageing concerning reverse lookup zones. Its absolutely essential to have them.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-09-2006 02:34 AM
тАО08-09-2006 02:34 AM
Re: Reverse Lookup zone benefits ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-09-2006 06:16 AM
тАО08-09-2006 06:16 AM
Re: Reverse Lookup zone benefits ?
>My servers will reject your mail out of hand if there is no reverse lookup zone
I also want to implement this ... what should I do in sendmail.mc ?
Regards
Maaz
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-09-2006 06:59 AM
тАО08-09-2006 06:59 AM
Re: Reverse Lookup zone benefits ?
http://networking.ringofsaturn.com/Unix/sendmailtips.php
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-09-2006 08:10 AM
тАО08-09-2006 08:10 AM
Re: Reverse Lookup zone benefits ?
from the tutorial(http://networking.ringofsaturn.com/Unix/sendmailtips.php)I copy paste the lines into my sendmail.cf, and then restart the service, error occured.
Plz check the attachment for the error
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-09-2006 08:13 AM
тАО08-09-2006 08:13 AM
Re: Reverse Lookup zone benefits ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-09-2006 08:59 AM
тАО08-09-2006 08:59 AM
Re: Reverse Lookup zone benefits ?
Add this to the end of your sendmail.mc file:
LOCAL_RULESETS
SLocal_check_relay
R$* $: $&{client_resolve}
RTEMP $#error $@ 4.7.1 $: "450 Access denied. Cannot resolve PTR record for " $&{client_addr}
RFORGED $#error $@ 4.7.1 $: "450 Access denied. IP name possibly forged " $&{client_name}
RFAIL $#error $@ 4.7.1 $: "450 Access denied. IP name lookup failed " $&{client_name}
Ensure that TAB is used to separate the right side with the left side.
Create your cf with:
m4 sendmail.mc sendmail.cf
Restar sendmail, you should not get errors.
Try again.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-10-2006 07:17 PM
тАО08-10-2006 07:17 PM
Re: Reverse Lookup zone benefits ?
Thanks Dear Ivan for such a nice/kind help
Ok I put the code into sendmail.cf file and then restart the sendmail, no error ;)
But when I telnet the server from client, following is the result
#telnet mail.test.com 25
220 localhost.localdomain ESMTP Sendmail 8.13.1/8.13.1; Fri, 11 Aug 2006 11:37:3
8 +0500
helo test.com
250 localhost.localdomain Hello pc1.test.com [10.0.0.1] (may be forged), pleas
ed to meet you
MAIL FROM:
450 4.7.1 Access denied. IP name possibly forged [10.0.0.1]
On sendmail server:
#tail -f /var/log/maillog
Aug 11 11:41:29 system2 sendmail[2787]: ruleset=check_relay, arg1=[10.0.0.1], arg2=10.0.0.1, relay=pc1.test.com [10.0.0.1] (may be forged), reject=450 4.7.1 Access denied. IP name possibly forged [10.0.0.1]
Bind and sendmail is configured on the same system(10.0.0.2)
on sendmail server:
#cat /etc/resolv.conf
nameserver 10.0.0.2
#cat /etc/named.conf
zone "0.0.10.in-addr.arpa" IN {
type master;
file "re";
};
zone "test.com" IN {
type master;
file "test.com.frwd";
};
file for reverse lookup zone is attached(/var/named/chroot/var/named/re)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-10-2006 07:19 PM
тАО08-10-2006 07:19 PM
Re: Reverse Lookup zone benefits ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-11-2006 01:59 AM
тАО08-11-2006 01:59 AM
Re: Reverse Lookup zone benefits ?
dig -x 10.0.0.1
Also, you can leave only the line that check for PTR and remove the others that check for forged addresses.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-12-2006 05:44 AM
тАО08-12-2006 05:44 AM
Re: Reverse Lookup zone benefits ?
dig -x 10.0.0.1 output is attached.
As per your instructions, I simply remove the "forged" line from sendmail.cf, and now its working ;).
from sendmail.cf:
SLocal_check_relay
R$* $: $&{client_resolve}
RTEMP $#error $@ 4.7.1 $: "450 Access denied. Cannot resolve PTR record for " $&{client_addr}
RFAIL $#error $@ 4.7.1 $: "450 Access denied. IP name lookup failed " $&{client_name}
May I know, why this line [ RFORGED $#error $@ 4.7.1 $: "450 Access denied. IP name possibly forged " $&{client_name}
] is not working properly ? even though IP to name resolution is working fine.
Refards
Maaz
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-12-2006 05:44 AM
тАО08-12-2006 05:44 AM
Re: Reverse Lookup zone benefits ?
dig -x 10.0.0.1 output is attached.
As per your instructions, I simply remove the "forged" line from sendmail.cf, and now its working ;).
from sendmail.cf:
SLocal_check_relay
R$* $: $&{client_resolve}
RTEMP $#error $@ 4.7.1 $: "450 Access denied. Cannot resolve PTR record for " $&{client_addr}
RFAIL $#error $@ 4.7.1 $: "450 Access denied. IP name lookup failed " $&{client_name}
May I know, why this line [ RFORGED $#error $@ 4.7.1 $: "450 Access denied. IP name possibly forged " $&{client_name}
] is not working properly ? even though IP to name resolution is working fine.
Regards
Maaz
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-12-2006 11:29 PM
тАО08-12-2006 11:29 PM
Re: Reverse Lookup zone benefits ?
The theory indicates that sendmail will try to do 2 lookups, a reverse lookup and a forward lookup. If the forward lookup does not match the information obtained in the reverse lookup, then considers the IP "forged".
Ensure that the A record and the PTR record resolves to the same hostname. If that is correct, then additional debugging is needed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-13-2006 10:09 AM
тАО08-13-2006 10:09 AM
Re: Reverse Lookup zone benefits ?
I can say that you are very generous man, thus awarding several times 10 points in the same thread.
Hence, I hoped that by complimenting you about your generosity, I could expect some points in return.
Forget my stupid joke :-)
Good lcuk.
Kodjo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-20-2006 03:42 AM
тАО08-20-2006 03:42 AM
Re: Reverse Lookup zone benefits ?
Dear Kodjo Agbenu, Well i think anyone who helps/reply..., takes out the time from his/her busy schedule. so I think I must appreciate ;). Believe me I have save my job several times... this forums and you GUYS are GENEROUS ;).
Thanks and Regards
Maaz