postfix-users

Re: A different kind of attack/probe, how can postfix defend against it?

Subject: Re: A different kind of attack/probe, how can postfix defend against it?
From: Listaccount <lst_hoe01 AT kwsoft DOT de>
To: postfix-users AT postfix DOT org
Date: Thu, 09 Aug 2007 21:28:29 +0200
Zitat von Justin Piszcz <jpiszcz AT lucidpixels DOT com>:

Recently, I saw this in my logs:

With iptables I guess I could specify something to block port 25 if it
gets hit too many times from _ANY_ ip but that would block legitimate
mail; however, it seems as if it the only or best option?

Aug  9 12:47:19 l2 postfix/smtpd[12676]: connect from
mx181.populationarea.com[69.31.50.181]
Aug  9 12:47:24 l2 postfix/smtpd[12676]: disconnect from
mx181.populationarea.com[69.31.50.181]
Aug  9 12:47:26 l2 postfix/smtpd[12676]: connect from
mx190.webcastersradio.com[69.31.50.190]
Aug  9 12:47:30 l2 postfix/smtpd[12676]: disconnect from
mx190.webcastersradio.com[69.31.50.190]
Aug  9 12:47:31 l2 postfix/smtpd[12676]: connect from
mx184.shippingkick.com[69.31.50.184]
Aug  9 12:47:35 l2 postfix/smtpd[12676]: disconnect from
mx184.shippingkick.com[69.31.50.184]

Hmm. I fail to see the problem. Beside noise in the logfile this should not hurt at all. It is at a rate well below 1/sec so this should not affect your mail service at all, so no need to defend postfix against it. And yes, we have this kind of connections all the time since many years on our mailrelay.

Regards

Andreas


<Prev in Thread] Current Thread [Next in Thread>