> > What else do you see?
>
>All I see are tons of these processes, after it gives the connect
>message, that's it. There are 3 days worth of logs that look like this!

That's it?  Just the connect and EHLO lines, nothing else (to MAIL FROM or 
RCPT TO or socket error lines, with the same frequency as the connect/EHLO 
lines)?  That is odd.

I would add 63.84.175.211 to the Control Access list in the SMTP security 
settings, to prevent them from connecting.  There is no valid reason for 
them to be doing whatever they are doing.

>What started me looking was that a few of my users have called me to
>advise that people have been trying to send them email and they have
>been getting bounce messages with non fatal errors. Could my poor server
>be so busy processing these pluto.thnetwork.net connections that it is
>ignoring legitimate mail?

Yes, that could be it.  They could be using up all the TCP connections, for 
example, if they are not disconnecting.

                                                    -Scott
---
Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for 
IMail.  http://www.declude.com

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Please visit the Knowledge Base for answers to frequently asked
questions:  http://www.ipswitch.com/support/IMail/

Reply via email to