[GLLUG] email troubles - lsd scnc server

Michael Rambo mrambo@scnc.lsd.k12.mi.us
Tue, 3 Dec 2002 14:24:35 -0500 (EST)


Hey all,

Lansing Schools just changed the range for their public IP's. Since that
change a very few of us have been unable to send messages to any address
outside of lsd.k12.mi.us. In fact it seems to be isolated to our shop. The
district mail server is a scnc box that (I think) is/was supplied by MSU.
Our network guy has called someone at MSU who apparently thinks it is
something with our shop server/router. We do not use our shop server to
transport mail - that goes directly to the scnc server in our mail
clients. Our shop server is for storage, routing, firewall, and
web/database purposes. We are basically getting a relaying denied message.
Here is what I see when I telnet to port 25 on the scnc box...

[mrambo@mrambo mrambo]$ telnet scnc.lsd.k12.mi.us 25
Trying 207.73.196.250...
Connected to scnc.lsd.k12.mi.us (207.73.196.250).
Escape character is '^]'.
220 scnc.lsd.k12.mi.us ESMTP Sendmail 8.10.2/8.10.2; Tue, 3 Dec 2002
08:17:24 -0500 (EST)
helo scnc.lsd.k12.mi.us
250 scnc.lsd.k12.mi.us Hello [207.73.232.115], pleased to meet you
mail from: mrambo@lsd.k12.mi.us
250 2.1.0 mrambo@lsd.k12.mi.us... Sender ok
rcpt to: munged@munged.net
550 5.7.1 munged@munged.net... Relaying denied. IP name lookup failed
[207.73.232.115]

The IP 207.73.232.115 is significant but I don't know where it comes from.
It was in the districts old IP range but should not be around any more. I
don't know why it's coming up as a response to the helo command. Our
workstations are NATted behind a firewall but that isn't the address - it
should be 10.8.24.7. In fact, after someone at MSU said our server/router
must be the problem I disconnected the outbound network card and tested my
laptop using the same ip address the server uses. My laptop fails when I
use the server ip address (10.8.24.7) but works if I change it to
10.8.24.5. This, I think, proves it isn't the server itself, but rather
some caching somewhere outside of our server.

I would just change the IP address on the box but that would create other
problems because of the vlan structure and traffic filtering in the high
schools.

Can anyone suggest where I can look for this problem. It's very much a
pain to have to use webmail or a dial-up account to send email when we
have full time connections right next to us.

Thanks.


--
Mike Rambo
mrambo@lsd.k12.mi.us