Bluehost.com Web Hosting $6.95

Re[2]: how to block connections at TCP level?

This is a discussion on Re[2]: how to block connections at TCP level? within the mailing.postfix.users forums, part of the Mail Servers and Related category; =FA=C4=D2=C1=D7=D3=D4=D7=D5=CA=D4=C5, Greg. =F7=D9 =D0=C9=D3=C1=CC=...


Go Back   Usenet Forums > Mail Servers and Related > mailing.postfix.users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-10-2004
Igor Lidin
 
Posts: n/a
Default Re[2]: how to block connections at TCP level?

=FA=C4=D2=C1=D7=D3=D4=D7=D5=CA=D4=C5, Greg.

=F7=D9 =D0=C9=D3=C1=CC=C9 9 =C6=C5=D7=D2=C1=CC=D1 2004 =C7., 23:17:44:

GAW> [ On Monday, February 9, 2004 at 18:49:32 (+0100), Tony Earnshaw wro=
te: ]
>> Subject: Re: how to block connections at TCP level?
>>
>> Postfix can not refuse at TCP level (OSI level 3). Your firewall can. =

An
>> alternative might be Wietse's tcp wrappers.


GAW> TCP Wrappers doesn't block at the TCP level -- In most TCP network
GAW> stacks the connection must be accepted before an application can
GAW> identify its source.

GAW> Besides, Postfix doesn't (and should not) use TCP Wrappers -- it has
GAW> much better SMTP-compatible client restrictions built into it.

Yes, surely. But when restriction is applyed at "recipient check" stage, =
the session is already established, and some bytes of traffic was sent an=
d received. Even when restriction triggers at "client check" stage, postf=
ix sends something like "554 service not available" and eats bytes of tra=
ffic.

You can say, "it is only about two dozens of bytes". Yes. One of my boxes=
that received 10 non-spam messages last month have 6 Gigs (!) of traffic=
.. Useless spam traffic.

Maybe at least "DISCONNECT" action in postfix maps may be implemented, wh=
ich, when triggered, disconnects client immediately.

Best wishes,
Igor Lidin

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 08:55 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0