From: klavs klavsen (
Date: Wed Mar 20 2002 - 12:26:16 EST

This is not really an appropriate discussion for the vserver list, but
here goes :-)

On Wed, 2002-03-20 at 17:33, wrote:
> I'm having a problem with sendmail on a vserver. When I send mail to the
> domain I keep getting refused connections. It looks to me like I have an
> ipchain issue in the main server but I'm not up enough on ipchains and how
> vserver handles the IP aliases for vservers.
if so, and you have set --log I believe it is on all your -j DENY lines
and end the chains with a DENY policy with a log all rule, you should
see the packets where your /etc/syslogd.conf logs kern.* (usually
/var/log/messages..) you can do "grep -irl kernel /var/log/*" to see
which file kernel logs to.
> Could some one that has sendmail accepting e-mail in a vserver send me a
> copy of their /etc/sysconfig/ipchains file? I hesitate to just disable
> ipchains to see if that is the problem because I've been hit a lot lately.
ipchains should not be your only defence - it shouldn't matter wether or
not you disable ipchains shortly.. clean up your netstat -nta and
netstat -nua output so no process listens, that you can't actually
trust. you should consider running portsentry also. If someone portscans
you, it will DENY them access to everything including otherwise allowed
services on the server.
> Or an good slap up along the side of the virtual head if I'm missing
> something really obvious.
most likely your sendmail is configured wrong.. try doing telnet to your
mailserver and see if you can send mail that way.. if you the banner
from the mailserver it's probably not an ipchains problem.

btw. you should consider changing to something like postfix - it's more
secure and it's a lot easier to setup as it uses a human readable
configuration file (i know sendmail has it's m4 assimilite config -
but's it not really that great if you ask me :-)

Klavs Klavsen

