syn flood generated by a postfix transaction

2020-09-10 Thread Gabriele Bulfon
Hello,   we recently had some situation of full bandwidth usage through our firewall, and by investigation we discovered that this was caused by a specific mail to a specific destination sent via Postifx 3.1.6. We found an ACK SYN DUP flood during the problem, many many packets sent, and this on

Re: syn flood generated by a postfix transaction

2020-09-10 Thread Wietse Venema
Gabriele Bulfon: > Hello, > we recently had some situation of full bandwidth usage through our > firewall, and by investigation we discovered that this was caused > by a specific mail to a specific destination sent via Postifx 3.1.6. > We found an ACK SYN DUP flood during the problem, many many pac

Re: syn flood generated by a postfix transaction

2020-09-10 Thread Gabriele Bulfon
Thanks so much for the deep explanation :)   Kernel is illumos, I exclude it can be a bug in the kernel stack. I will check Postfix config, but I don't think there is any huge limit as you suggested.   What about the "PIX workaround"? Can it be something causing this? It did not happen on a previ

Re: syn flood generated by a postfix transaction

2020-09-10 Thread Wietse Venema
Gabriele Bulfon: > Thanks so much for the deep explanation :) Considering the questions asked, I must keep the conversation at a basic level. > Kernel is illumos, I exclude it can be a bug in the kernel stack. > I will check Postfix config, but I don't think there is any huge > limit as you sugge