This has been a niggling problem for some time. The problem is my clients get long email delays (to the point of getting timeouts). All their email goes through a spam gateway on a firewall DMZ then is relayed to my Dathorn mail server where they pick it up typically via POP3.
I notice my firewall logs have a huge amount of entries logged as "syn flood attack" between my spam gateway and the mail server". The firewall has Syn Cookies enabled. I also set rules in the firewall to allow the relevant port (113) between the gateway and the mail servers but does not seem to have any effect.
I am sure the email delays and the "Syn" activity are related.
Is there anything I can do - at either end - to stop or reduce all the "Syn" activity? Should I disable syn-cookies on the firewall?
Cheers
Kirby
I notice my firewall logs have a huge amount of entries logged as "syn flood attack" between my spam gateway and the mail server". The firewall has Syn Cookies enabled. I also set rules in the firewall to allow the relevant port (113) between the gateway and the mail servers but does not seem to have any effect.
I am sure the email delays and the "Syn" activity are related.
Is there anything I can do - at either end - to stop or reduce all the "Syn" activity? Should I disable syn-cookies on the firewall?
Cheers
Kirby