Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Slow connection to SMTP service

Hi. I am seeking guidance on trying to track down a problem that has recently appeared. We use a FG500A v4.0,build0291,100824 (MR2 Patch 2) Basically, in the last week or so, opening connections to the SMTP service on our mail server have slowed from being sub second to now taking over 10 seconds to connect. Once connection is established (HELLO message from SMTP server appears) then the actual throughput is fine. Using telnet, I opened a link to port 25 on the server using it' s ip address from the server itself, a machine on the same local network behind the firewall and a remote machine outside the firewall. The connection on the local network and outside the network take ages to connect. The connection on the machine itself, using it' s ip address or 127.0.0.1 happen straight away. POP3 connections to the same server connect straight away and do not have this issue. The mail server has been rebooted several times. I have turned off UTM in the firewall policy to no effect. No changes were done to either firewall or mail server before the problem appeared. As the link on the local mail server happens straight away, I am unsure as to where the issue may lie (firewall or mail server) and really where to start? Any advice welcome! Thank you in advance. Penny
4 REPLIES 4
rwpatterson
Valued Contributor III

Confirm the connections are good. Sound cable, no duplex issues, etc.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

Confirm the connections are good. Sound cable, no duplex issues, etc.
Everything else on the mail server works fine (POP3, IMAP, Web interface, etc.) and there are actually no errors with the SMTP, just the initial delay. My thoughts were along the lines of could it be the blacklist or dns checking, something that might affect a SMTP connection only. But any clues or suggestions, are most welcome. Penny
Carl_Wallmark
Valued Contributor

hi, i have three possible things: 1. Have you configured for the FG to check against RBL servers ? 2. Slow connection to the FortiGuard Antispam Service 3. Somehow the mail server delayes the traffic from the internet, there are settings on almost every mail server to pass a delay for the first initial contact, i would try to sniff the traffic with something like this: diag sni pack wan1 ' port 25' 4 and in another window at the same time diag sni pack internal ' port 25' 4

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Not applicable

Finally found the issue. The SMTP server had an obscure section in the configuration for DNSBL if there was more than one DNSBL to check, and one of the servers in there (rbl.maps.vix.com) has obviously gone out of service. Replaced that and all is good. Thank you for all advice.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors