[lug] SMTP delivery: No route to host

Justin-lists glow at jackmoves.com
Sat Nov 23 15:23:21 MST 2002


Here is the tcpdump from the client where I am sending the mail from.

[root at sirius log]# tcpdump
tcpdump: listening on eth0
15:25:16.985362 192.168.1.6.32825 > ns.jackmoves.com.domain:  5961+ A?
jackmoves.com. (31) (DF)
15:25:16.986863 192.168.1.6.32826 > ns.jackmoves.com.domain:  7093+ PTR?
6.1.168.192.in-addr.arpa. (42) (DF)
15:25:17.172184 ns.jackmoves.com.domain > 192.168.1.6.32825:  5961* 1/1/1 A
jackmoves.com (80)
15:25:17.172636 192.168.1.6.33589 > jackmoves.com.smtp: S
167123173:167123173(0) win 5840 <mss 1460,sackOK,timestamp 69651041
0,nop,wscale 0> (DF)
15:25:17.191996 ns.jackmoves.com.domain > 192.168.1.6.32826:  7093 NXDomain*
0/1/0 (119)
15:25:17.192642 192.168.1.6.32826 > ns.jackmoves.com.domain:  7094+ PTR?
71.117.247.206.in-addr.arpa. (45) (DF)
15:25:17.282138 wc-bb-cogent.wcox.com > 192.168.1.6: icmp: host jackmoves.com
unreachable - admin prohibited filter
15:25:17.362155 ns.jackmoves.com.domain > 192.168.1.6.32826:  7094* 1/1/1 (105)
15:25:17.421688 192.168.1.6.32826 > ns.jackmoves.com.domain:  7095+ PTR?
72.117.247.206.in-addr.arpa. (45) (DF)
15:25:17.592192 ns.jackmoves.com.domain > 192.168.1.6.32826:  7095* 1/1/1 (105)
15:25:17.592980 192.168.1.6.32826 > ns.jackmoves.com.domain:  7096+ PTR?
1.192.252.66.in-addr.arpa. (43) (DF)
15:25:17.782272 ns.jackmoves.com.domain > 192.168.1.6.32826:  7096 1/3/3 (182)
15:25:21.984260 arp who-has 192.168.1.1 tell 192.168.1.6
15:25:21.984451 arp reply 192.168.1.1 is-at 0:48:54:8c:78:b3
15:25:21.984814 192.168.1.6.32826 > ns.jackmoves.com.domain:  7097+ PTR?
1.1.168.192.in-addr.arpa. (42) (DF)
15:25:22.163414 ns.jackmoves.com.domain > 192.168.1.6.32826:  7097 NXDomain*
0/1/0 (119)
15:25:27.164444 arp who-has 192.168.1.6 tell 192.168.1.1
15:25:27.164487 arp reply 192.168.1.6 is-at 0:1:2:5e:ea:bd

18 packets received by filter
0 packets dropped by kernel

What does the "admin prohibited filter" mean? 

Justin

--
glow at jackmoves.com


---------- Original Message -----------
From: rm at fabula.de
To: lug at lug.boulder.co.us
Sent: Sat, 23 Nov 2002 22:55:41 +0100
Subject: Re: [lug] SMTP delivery: No route to host


> That indeed sounds strange. Can you do a tcpdump to capture the traffic?
> I bet you there's some incomming icmp packet that informs your server
> about that fact. Try to figure out which router did send this 
> package. Is anything inbetween blocking SMTP?
> 
> hth ralfd
> _______________________________________________
> Web Page:  http://lug.boulder.co.us
> Mailing List: http://lists.lug.boulder.co.us/mailman/listinfo/lug
> Join us on IRC: lug.boulder.co.us port=6667 channel=#colug
------- End of Original Message -------




More information about the LUG mailing list