You were lucky .... this time :))
>We have a problem with people using software that would try many names
>like:
dumb@ss dictionary attack
>It really dragged down server. They run all night and when we check server
>in morning it is dog slow.
... resuting in DoS for your users.
This is the leading, dominant reason why we don't want to dump
anti-spam, anti-virus, anti-relay, MAPS/ORBS, DNS validations onto
the "users' box", aka Imail, but hide the users' box, aka "your
moneymaker", behind a project like IMGate that would have stopped
every byte of this DoS if the @sshole was on DUL. ie, having a
second box is not a pain, but the principal advantage.
Also, reversing the ip address 216.28.79.149 fails, so IMGate would
have stopped him that way, too.
With two IMGate boxes as primary and secondary MX's and the secondary
MX also as your Imail outgoing gateway, the primary IMGate could have
been fully occupied holding castle gates shut while users were
reading their POP and sending mail through Imail plsu 2ndary MX,
users not even aware that IMGate 1 was suffering DoS.
If the DoS gets so severe that MX 10 can't respond, then Internet
servers will try the loafing MX 20 and the incoming will get through
to Imail by that door, since MX 20, being smarted up by our config,
relays straight to Imail, NOT back to MX 10 (as customarily would be the case).
Len
http://BIND8NT.MEIway.com: ISC BIND 8.2.2 p5 installable binary for NT4
http://IMGate.MEIway.com: Build free, hi-perf, anti-spam mail gateways
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/