Bluehost.com Web Hosting $6.95

Re[2]: how to block connections at TCP level?

This is a discussion on Re[2]: how to block connections at TCP level? within the mailing.postfix.users forums, part of the Mail Servers and Related category; >> Is there any possibility to block incoming SMTP connections to port >> 25 controlled by postfix at ...


Go Back   Usenet Forums > Mail Servers and Related > mailing.postfix.users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-10-2004
Igor Lidin
 
Posts: n/a
Default Re[2]: how to block connections at TCP level?

>> Is there any possibility to block incoming SMTP connections to port
>> 25 controlled by postfix at TCP level (e.g. refuse connection or at
>> least disconnect immediately) using filtering rules already supported by
>> postfix - cidr maps, tcp maps, dnsbl checks and so on?


TE> Postfix can not refuse at TCP level (OSI level 3). Your firewall can. An
TE> alternative might be Wietse's tcp wrappers.

Sadly, firewall CAN NOT refuse connection using DNSBL check on originating address.

>> It is needed because of huge traffic amount that eated by useless
>> spam connections (e.g. from *.ipt.aol.com) that are filtered anyway at
>> "client" stage.
>>
>> It may be implemented as something like smtpd_tcp_restrictions configuration variable.


TE> Don't see how. I block via Postfix using smtpd_recipient_restrictions.
TE> That works fine for me (at the moment I'm blocking up to 40% of all MAIL
TE> FROM:/RCPT TO: offerings), but YMMV. BTW, this has risen from around
TE> 10-15% within the last week.

When you block at this stage, some amount of traffic already passed. Ideally (for me), postfix should refuse connections from, say, dynamically allocated IPs using some blacklist. Practically, I think, at least some sort of DISCONNECT action in maps can be implemented to reduce traffic amount used by useless connections.

Best wishes,
Igor Lidin

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 07:43 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0