I had this 6 months ago on a another mail system . If you use Cisco Routers you can do connection tarring on the inbound, They give up when the connection gets very slow. Unless it's a script and they guy is off watching CNN
The other way is to see if the inbound IP is a Cable/DSL/Dialup , Enable a Dialup-RBL for a few hours and he will get board when your mail server seems to vanish from existence. My 2c -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Len Conrad Sent: Friday, 18 June 2004 11:30 a.m. To: [EMAIL PROTECTED] Subject: RE: [IMail Forum] Getiing bombed >To known users. that's a bitch, as always. you harvest the IPs from the imail log, and do tcp-block of the highest volume IPs and/or ClassCs at your packet filter (use PktFilter right on the Imail box). and/or do content-scanning where the rule-match action is DISCARD (accept and silently drop) rather than REJECT (don't accept). You don't want to reject known virus msgs, since that makes you an accomplice in the virus propagation. Len _____________________________________________________________________ http://MenAndMice.com/DNS-training : Denver; NYC; San Jose http://IMGate.MEIway.com : free anti-spam gateway, runs on 1000's of sites To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
