Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SMTP Issue - Hostgator and KingHost

    Scheduled Pinned Locked Moved General pfSense Questions
    12 Posts 4 Posters 466 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      antonioremigio1
      last edited by

      Hey everyone, how’s it going?

      I’m experiencing a weird issue and would like your input.

      I have two separate hosts, each with its own independent pfSense.

      For the past week, on Host 1, I haven’t been able to establish a telnet connection to port 587 on Hostgator’s SMTP. And as of today (30/09), the same issue started happening with KingHost's SMTP as well. I can still ping the SMTP servers, but the telnet connection on port 587 fails.

      On Host 2, everything works normally and telnet connects without any issues.

      We opened a ticket with Hostgator, and they confirmed that our IP is NOT blocked (which makes sense since I can ping the server).

      Here’s what the pfSense log shows:

      0eee6faf-e620-4822-a66a-3b9bb6f2c67e-image.png

      I’m not using any proxy, and the outbound traffic is completely allowed.

      Has anyone experienced something similar?

      Thanks!

      johnpozJ GertjanG 2 Replies Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @antonioremigio1
        last edited by johnpoz

        @antonioremigio1 looks like they never answered you syn..

        Which would scream they are blocking your IP to me to be honest.. I just tried connecting to them

        Trying 192.185.177.60...
        Connected to 192.185.177.60.
        Escape character is '^]'.
        220-br184.hostgator.com.br ESMTP Exim 4.96.2 #2 Mon, 30 Sep 2024 22:50:31 -0300 
        220-We do not authorize the use of this system to transport unsolicited, 
        

        If they are not blocking your IP, something between you and them maybe.. Something upstream of you blocking 587?

        Or maybe you got back a rst, if you looked at your states right away and seeing closed, maybe they sent a rst.. I would sniff on pfsense wan when you try and open the connection.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        A 1 Reply Last reply Reply Quote 2
        • A
          antonioremigio1 @johnpoz
          last edited by

          Hello @johnpoz,

          Thanks for your reply.

          Capturing packets from the WAN, it shows like this:

          10:23:01.221460 IP MY_IP.14054 > 191.6.220.63.587: tcp 0
          10:23:09.230543 IP MY_IP.14054 > 191.6.220.63.587: tcp 0
          10:24:29.122553 IP MY_IP.11360 > 191.6.220.63.587: tcp 0
          10:24:29.122636 IP MY_IP.7203 > 191.6.220.63.587: tcp 0
          10:24:29.285716 IP MY_IP.39871 > 191.6.220.63.587: tcp 0
          10:24:30.126378 IP MY_IP.7203 > 191.6.220.63.587: tcp 0
          10:24:30.126476 IP MY_IP.11360 > 191.6.220.63.587: tcp 0
          10:24:30.298397 IP MY_IP.39871 > 191.6.220.63.587: tcp 0
          10:24:32.126268 IP MY_IP.7203 > 191.6.220.63.587: tcp 0
          10:24:32.126304 IP MY_IP.11360 > 191.6.220.63.587: tcp 0
          10:24:32.313791 IP MY_IP.39871 > 191.6.220.63.587: tcp 0
          10:24:36.126446 IP MY_IP.11360 > 191.6.220.63.587: tcp 0
          10:24:36.141969 IP MY_IP.7203 > 191.6.220.63.587: tcp 0
          10:24:36.313947 IP MY_IP.39871 > 191.6.220.63.587: tcp 0
          10:24:44.142201 IP MY_IP.11360 > 191.6.220.63.587: tcp 0
          10:24:44.157670 IP MY_IP.7203 > 191.6.220.63.587: tcp 0
          10:24:44.329661 IP MY_IP.39871 > 191.6.220.63.587: tcp 0

          Thank's.

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @antonioremigio1
            last edited by

            @antonioremigio1 so you never get anything back from them. Either they just dropping your traffic or it never gets to them because of a block between you and them on 587.

            Or they are blocking you and the prob level 1 guy you talking to didn't have a clue..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 1
            • GertjanG
              Gertjan @antonioremigio1
              last edited by Gertjan

              @antonioremigio1

              Same thing here :

              220-br184.hostgator.com.br ESMTP Exim 4.96.2 #2 Tue, 01 Oct 2024 10:50:02 -0300
              220-We do not authorize the use of this system to transport unsolicited,
              220 and/or bulk e-mail.
              HELO me.com
              250 br184.hostgator.com.br Hello laubervilliers-658-1-179-108.w82-127.abo.wanadoo.fr [82.127.62.180]
              quit
              

              Answers just fine.

              Btw : Hosting a (whatever) server means often therein is a fail2ban or comparable protection mechanism that scans the logs of the server you try to contact. If there are to many failed attempts, lets say 3 within 10 minutes, the IP gets banned. This happens more then you think, as we all think we know our mail password ;)
              Normally, when banning arrives, a firewall gets injected that blocks "the IP using port '587' TCP" (in this case) so you will still be able to contact port 443 TCP so you can still connect to the web interface - if any - or use the POP or IMAP access.

              And yeah, TCP is not ICMP.

              The guy that can tell you that your are blocked is normally not the one you can get on the phone.
              IPv4 on the block lists don't stay blocked for ever, as that is impossible : over time, the blacklist would contain every possible IPv4 ... so they are releases after 'some time'.

              Here you have my fail2ban stats..

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              A 1 Reply Last reply Reply Quote 1
              • A
                antonioremigio1 @Gertjan
                last edited by

                Alright @Gertjan,

                But is this rule automatically created by pfSense?

                The Hostgator SMTP started working again without me taking any action on my firewall, only Kinghost's SMTP is still blocked.

                I’m 99% sure the block is on their end.

                I’m waiting for support to reply.

                I’ll update here once I have any news.

                Thanks.

                stephenw10S GertjanG 2 Replies Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator @antonioremigio1
                  last edited by

                  @antonioremigio1 said in SMTP Issue - Hostgator and KingHost:

                  is this rule automatically created by pfSense?

                  No it's at the mail server end. Nothing you can do about it but wait for it to expire usually.

                  1 Reply Last reply Reply Quote 1
                  • GertjanG
                    Gertjan @antonioremigio1
                    last edited by

                    @antonioremigio1 said in SMTP Issue - Hostgator and KingHost:

                    The Hostgator SMTP started working again without me taking any action on my firewall, only Kinghost's SMTP is still blocked.

                    I’m 99% sure the block is on their end.

                    Exact. Proves somewhat my point : the fail2ban story. The block was only temporary.
                    You can easily test all this : use telnet on port 587 to login manually, like a mail client does.
                    But : do not use the correct password. Within minutes of testing, you will get blocked.
                    And unblocked xx hours later, as you've seen.

                    The mentioned fail2ban process (run on the server) puts firewall rules on the (mail) server to block users that 'fail' something, mostly : wrong password. Think about password guessing scripts ....

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    A 1 Reply Last reply Reply Quote 1
                    • A
                      antonioremigio1 @Gertjan
                      last edited by

                      @Gertjan

                      Solved:

                      Hey everyone,

                      It worked, the issue was a block on the email provider's side.

                      They unblocked my IP, and email sending is working again.

                      Thank you all for your support.

                      Cheers!

                      johnpozJ 1 Reply Last reply Reply Quote 1
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @antonioremigio1
                        last edited by

                        @antonioremigio1 said in SMTP Issue - Hostgator and KingHost:

                        It worked, the issue was a block on the email provider's side.

                        So like I thought the first guy you talked to "opened a ticket with Hostgator, and they confirmed that our IP is NOT blocked" was some idiot without a clue ;)

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        A 1 Reply Last reply Reply Quote 1
                        • A
                          antonioremigio1 @johnpoz
                          last edited by

                          @johnpoz

                          Hahaha

                          Qualified professional lol

                          Thanks for the support.

                          johnpozJ 1 Reply Last reply Reply Quote 0
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator @antonioremigio1
                            last edited by

                            @antonioremigio1 Hope gave them a bit of business end about - thought you said our IP wasn't blocked ;)

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.