Hi There,
Here is the log file to compare with the nagios screen dump
My internal ip is 192.168.1.5 public ip is 80.127.x.x
Thank you in forward
Apr 29 09:58:04 zimbra zimbramon[3157]: 3157:info: 2009-04-29 09:58:01, STATUS: zimbra.mydomain.nl: mailbox: Running
Apr 29 09:58:04 zimbra zimbramon[3157]: 3157:info: 2009-04-29 09:58:01, STATUS: zimbra.mydomain.nl: mta: Running
Apr 29 09:58:04 zimbra zimbramon[3157]: 3157:info: 2009-04-29 09:58:01, STATUS: zimbra.mydomain.nl: snmp: Running
Apr 29 09:58:04 zimbra zimbramon[3157]: 3157:info: 2009-04-29 09:58:01, STATUS: zimbra.mydomain.nl: spell: Running
Apr 29 09:58:04 zimbra zimbramon[3157]: 3157:info: 2009-04-29 09:58:01, STATUS: zimbra.mydomain.nl: stats: Running
Apr 29 09:58:10 zimbra kernel: Shorewall:net2all

ROP:IN=eth0 OUT= MAC=00:30:48:60:46:9e:00:19:cb:89:e2:f6:08:00 SRC=87.106.7.213 DST=80.127.x.x LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=25246 DF PROTO=TCP SPT=1183 DPT=1433 WINDOW=65535 RES=0x00 SYN URGP=0
Apr 29 09:58:13 zimbra kernel: Shorewall:net2all

ROP:IN=eth0 OUT= MAC=00:30:48:60:46:9e:00:19:cb:89:e2:f6:08:00 SRC=87.106.7.213 DST=80.127.x.x LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=27175 DF PROTO=TCP SPT=1183 DPT=1433 WINDOW=65535 RES=0x00 SYN URGP=0
Apr 29 09:58:29 zimbra kernel: Shorewall:net2all

ROP:IN=eth0 OUT= MAC=00:30:48:60:46:9e:00:19:cb:89:e2:f6:08:00 SRC=202.170.126.219 DST=80.127.x.x LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=22358 DF PROTO=TCP SPT=1909 DPT=4899 WINDOW=65535 RES=0x00 SYN URGP=0
Apr 29 09:58:32 zimbra kernel: Shorewall:net2all

ROP:IN=eth0 OUT= MAC=00:30:48:60:46:9e:00:19:cb:89:e2:f6:08:00 SRC=202.170.126.219 DST=80.127.x.x LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=24532 DF PROTO=TCP SPT=1909 DPT=4899 WINDOW=65535 RES=0x00 SYN URGP=0
Apr 29 09:59:15 zimbra kernel: Shorewall:all2all:REJECT:IN= OUT=eth1 SRC=80.127.x.x DST=80.69.93.212 LEN=76 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=123 DPT=123 LEN=56
Apr 29 10:00:01 zimbra zimbramon[3829]: 3829:info: 2009-04-29 10:00:01, QUEUE: 0 0
Apr 29 10:00:02 zimbra zimbramon[3836]: 3836:info: 2009-04-29 10:00:01, DISK: zimbra.mydomain.nl: dev: /dev/mapper/vbzimbra-root, mp: /, tot: 148929, avail: 133058
Apr 29 10:00:02 zimbra zimbramon[3836]: 3836:info: 2009-04-29 10:00:01, DISK: zimbra.mydomain.nl: dev: /dev/mapper/vbzimbra-boot, mp: /boot, tot: 198, avail: 169
Apr 29 10:00:04 zimbra zimbramon[3838]: 3838:info: 2009-04-29 10:00:01, STATUS: zimbra.mydomain.nl: antispam: Running
Apr 29 10:00:04 zimbra zimbramon[3838]: 3838:info: 2009-04-29 10:00:01, STATUS: zimbra.mydomain.nl: antivirus: Running
Apr 29 10:00:04 zimbra zimbramon[3838]: 3838:info: 2009-04-29 10:00:01, STATUS: zimbra.mydomain.nl: ldap: Running
Apr 29 10:00:04 zimbra zimbramon[3838]: 3838:info: 2009-04-29 10:00:01, STATUS: zimbra.mydomain.nl: logger: Running
Apr 29 10:00:04 zimbra zimbramon[3838]: 3838:info: 2009-04-29 10:00:01, STATUS: zimbra.mydomain.nl: mailbox: Running
Apr 29 10:00:04 zimbra zimbramon[3838]: 3838:info: 2009-04-29 10:00:01, STATUS: zimbra.mydomain.nl: mta: Running
Apr 29 10:00:04 zimbra zimbramon[3838]: 3838:info: 2009-04-29 10:00:01, STATUS: zimbra.mydomain.nl: snmp: Running
Apr 29 10:00:04 zimbra zimbramon[3838]: 3838:info: 2009-04-29 10:00:01, STATUS: zimbra.mydomain.nl: spell: Running
Apr 29 10:00:04 zimbra zimbramon[3838]: 3838:info: 2009-04-29 10:00:01, STATUS: zimbra.mydomain.nl: stats: Running
Apr 29 10:01:34 zimbra kernel: Shorewall:all2all:REJECT:IN=eth1 OUT= MAC=00:30:48:60:46:9f:00:1f:29:b5:0c:56:08:00 SRC=192.168.1.77 DST=192.168.1.5 LEN=105 TOS=0x00 PREC=0x00 TTL=128 ID=25862 PROTO=UDP SPT=1029 DPT=161 LEN=85
Apr 29 10:01:40 zimbra kernel: Shorewall:all2all:REJECT:IN=eth1 OUT= MAC=00:30:48:60:46:9f:00:1f:29:b5:0c:56:08:00 SRC=192.168.1.77 DST=192.168.1.5 LEN=105 TOS=0x00 PREC=0x00 TTL=128 ID=25867 PROTO=UDP SPT=1029 DPT=161 LEN=85
Apr 29 10:01:46 zimbra kernel: Shorewall:all2all:REJECT:IN=eth1 OUT= MAC=00:30:48:60:46:9f:00:1f:29:b5:0c:56:08:00 SRC=192.168.1.77 DST=192.168.1.5 LEN=105 TOS=0x00 PREC=0x00 TTL=128 ID=25871 PROTO=UDP SPT=1029 DPT=161 LEN=85
Apr 29 10:01:52 zimbra kernel: Shorewall:all2all:REJECT:IN=eth1 OUT= MAC=00:30:48:60:46:9f:00:1f:29:b5:0c:56:08:00 SRC=192.168.1.77 DST=192.168.1.5 LEN=105 TOS=0x00 PREC=0x00 TTL=128 ID=25897 PROTO=UDP SPT=1029 DPT=161 LEN=85
I am smelling a firewall problem but the strange thing is that even with the firewall off the problem does exist !