pop3 & imap radical slowdown

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

pop3 & imap radical slowdown

Postby truhla » Mon Aug 19, 2002 4:18 pm

this happens only if grsec_stealth_rst flag is set...
but, the other machine i am running linux + grsec on, this happens not.

is this a programming issue, or ?
truhla
 
Posts: 2
Joined: Mon Aug 19, 2002 4:11 pm

Postby torne » Tue Aug 20, 2002 4:34 am

Do you mean an IMAP/POP server running on your machine, or that you're connecting to IMAP/POP servers from your machine? If the latter, the first thing to check is whether the server is trying to query your identd. If you don't have an identd server running and you're running in stealth mode, it will take anything up to a minute or two to log in to a service which checks for it (some servers, IRC..etc) because your machine is ignoring the connections on port 113.

If that's not the problem, then you'll have to wait for someone else to come along with a suggestion, but that was why my machine took several minutes to log in to IRC. I fixed it by changing my firewall rules to explicitly reject connections to the ports that the server was querying with a TCP RST (the server in question was doing open proxy checks as well as identd).

Torne
torne
 
Posts: 54
Joined: Mon Aug 12, 2002 12:52 pm

Postby spender » Wed Aug 21, 2002 9:17 am

Also, update your version of grsecurity. the stealth networking options were converted to a netfilter module months ago.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm


Return to grsecurity support