> > > How would I  totaly block
> > >
> > > 63.xx.xx.xx ??
> >
> > 63.0.0.0    255.0.0.0
>
>I did that... but just got attacked from
>63.228.107.59 an hour later.

This looks like DUL "pool" doo doo to me:

# dig -x 63.228.107.59

; <<>> DiG 8.2 <<>> -x
;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 3
;; QUERY SECTION:
;;      59.107.228.63.in-addr.arpa, type = ANY, class = IN

;; ANSWER SECTION:
59.107.228.63.in-addr.arpa.  1D IN PTR  sttlnas67poolA59.sttl.uswest.net.

If you had IMGate out front AND this was not a spoofed sender ip but 
an actual MAPS ip, then your Imgate would absorb the DoS by rejecting 
the connnection from DUL, IMail would see nothing.

You can't really stop a DoS, so it's much better to have a 
non-mailbox gateway server fend off / absorb the attacks. iow, a one 
box solution just doesn't hack it when the going gets rough.

Len



http://BIND8NT.MEIway.com : Binary for ISC BIND 8.2.3 T9B for NT4 & W2K
http://IMGate.MEIway.com  : Build free, hi-perf, anti-spam mail gateways

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to