My problem is this, I have a Scalix 11.2 server that has been running great for the last 3 or 4 months. Until the last week or so it started crashing, well users complained of not getting emails. At first I would just reboot and everything started working again so I thought nothing of it. However it has progressed to an few hour thing. In looking @ the messages log I see the following ...
Mar 19 11:15:48 mail omslapd[16255]: conn=5055 op=0 RESULT err=0 tag=101 nentries=0
Mar 19 11:15:49 mail omslapd[16255]: conn=5055 op=1 UNBIND
Mar 19 11:15:49 mail omslapd[16255]: conn=5055 op=1 fd=9 closed errno=0
Mar 19 11:15:52 mail nss_wins[27177]: m2HMCNM2013519: to=<plebiscite@yahoo.com>, delay=1+19:03:29, xdelay=00:00:03, mailer=esmtp, pri=5882723, relay=d.mx.mail.yahoo.com. [66.196.82.7], dsn=4.0.0, stat=Deferred: 421 4.7.0 [TS01] Messages from 64.122.176.57 temporarily deferred due to user complaints - 4.16.55.1; see http://postmaster.yahoo.com/421-ts01.html
Mar 19 11:15:54 mail omslapd[16255]: conn=5056 fd=9 connection from unknown (192.168.0.250)
Mar 19 11:15:54 mail omslapd[16255]: conn=5056 op=0 SRCH base="o=scalix" scope=2 filter="(&(|(&(objectclass=scalixPerson)(omulcaps=*))(objectclass=scalixDistributionList)(sn=+bb))(mail=scratching@yahoo.com))"
Mar 19 11:15:54 mail omslapd[16255]: conn=5056 op=0 RESULT err=0 tag=101 nentries=0
Mar 19 11:15:55 mail omslapd[16255]: conn=5056 op=1 UNBIND
Mar 19 11:15:55 mail omslapd[16255]: conn=5056 op=1 fd=9 closed errno=0
Mar 19 11:15:56 mail nss_wins[27177]: m2HMO8Jm016182: to=<scratching@yahoo.com>, delay=1+18:51:48, xdelay=00:00:01, mailer=esmtp, pri=5972723, relay=c.mx.mail.yahoo.com. [216.39.53.3], dsn=2.0.0, stat=Sent (ok dirdel)
Mar 19 11:15:56 mail omslapd[16255]: conn=5057 fd=9 connection from unknown (192.168.0.250)
Mar 19 11:15:56 mail omslapd[16255]: conn=5057 op=0 SRCH base="o=scalix" scope=2 filter="(&(|(&(objectclass=scalixPerson)(omulcaps=*))(objectclass=scalixDistributionList)(sn=+bb))(mail=sarcastic@yahoo.com))"
these messages just keep growing. Also in my 'root' mail I am seeing stuff like this ...
Return-Path: <excavations@yahoo.com>
Received: from mail.statewideslc.com (localhost [127.0.0.1])
by mail.statewideslc.com (8.13.6/8.13.6/SuSE Linux 0.
for <snq@telekbird.com.cn>; Thu, 13 Mar 2008 12:10:02 -0600
Received: from pockets ( [82.119.92.103])
by mail.statewideslc.com (Scalix SMTP Relay 11.0.4.10790)
via ESMTP; Thu, 13 Mar 2008 12:06:51 -0600 (MDT)
Date: Thu, 13 Mar 2008 17:12:33 +0000
From: "Meg Garcia"<excavations@yahoo.com>
To: snq@telekbird.com.cn
Message-ID: <6850.20131205431612.mail.statewideslc.com@MHS>
Subject: re:re:first
x-scalix-Hops: 1
Mime-Version: 1.0
Content-Type: text/html
Content-Disposition: inline
X-Spam-Flag: YES
X-Spam-Status: Yes, score=13.1 required=5.0 tests=BAYES_99,FORGED_YAHOO_RCVD,
HTML_COMMENT_SAVED_URL,HTML_IMAGE_ONLY_08,HTML_MESSAGE,
HTML_SHORT_LINK_IMG_1,MIME_HTML_ONLY autolearn=no version=3.1.3
X-Spam-Level: *************
X-Spam-Checker-Version: SpamAssassin 3.1.3 (2006-06-01) on
mail.statewideslc.com
What stands out to me is Received: from pockets ( [82.119.92.103]) but I have the following in my smtpd.cfg which should prevent me from being used as a 'relay'
RELAY accept 127.0.0.1
RELAY accept .statewideslc.com
RELAY accept 192.168.0.
RELAY Log_Reject ALL
so I don't know what to make of this Received: from pockets ( [82.119.92.103]) at least to me it looks like it's originating there.
