juan smitt:
[using smtpd_client_connection_count_limit for traffic management]
> Unfortunately the service (which is made of 4 servers) is behind a
> firewall which hides the real client IPs so these 4 servers see only 1
> client (the firewall) and the expected mail count is 4+ million per
> day.
This is a terrible idea, because the server cannot distinguish
between different clients, and therefore you can't 'punish' a bad
client with client-based policies. You punish them all.
Please consider using something like HaProxy, which can inform
Postfix of the remote SMTP client IP address and thus enables more
meaningful policies.
Wietse