[mdaemon-l] Connection Refuse

2020-11-17 Terurut Topik Syafril Hermansyah via mdaemon-l


On 17/11/20 15.22, Bambang Setiawan via mdaemon-l wrote:
>> Cari di smtp-in log 2020-11-16 berkisar jam 10 - 11.18 apakah ada transaksi
>> dari 103.69.140.247 [sinsgout.his.huawei.com] yang ditolak karena kirim
>> mail ke banyak unknown recipient.
> 
> Sepertinya ini log terakhirnya pak,


Ya benar.

> Mon 2020-11-16 11:18:59.471: 01: [07641866] More than 5 RCPT commands 
> encountered; this session tarpitted with a 10 second initial delay scaling by 
> 1.00


Non aktifkan saja tarpit yang memperlambat incoming mail.

http://mdaemon.dutaint.co.id/mdaemon/20.0/index.html?security--tarpit_settings.htm

> Baik Pak, saya sudah sesuaikan seperti yang Bapak sarankan.
> 
> Jika saya aktifkan kembali dynamic screening dengan opsi yang sudah 
> disesuaikan apakah harusnya sudah normal kembali mail server saya pak.


Kalau isian dynamic blacklist sudah dihapus, mestinya pengaktifan dynamic
screening akan ok saja.

http://mdaemon.dutaint.co.id/mdaemon/20.0/index.html?dynamic-screening_dynamic-blacklist.htm

-- 
syafril

Syafril Hermansyah

MDaemon-L Moderator, run MDaemon 20.5.0 64bit Beta B
Mohon tidak kirim private mail (atau cc:) untuk masalah MDaemon.

We do not remember days, we remember moments.
--- Cesare Pavese


-- 
--[mdaemon-l]--
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server di Indonesia

Netiket: https://wiki.openstack.org/wiki/MailingListEtiquette
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Berlangganan: Kirim mail ke mdaemon-l-subscr...@dutaint.com
Henti Langgan: Kirim mail ke mdaemon-l-unsubscr...@dutaint.com
Versi terakhir: MDaemon 20.0.3, SecurityGateway 7.0.1




[mdaemon-l] Connection Refuse

2020-11-17 Terurut Topik Bambang Setiawan via mdaemon-l



On 17/11/2020 13.41, Syafril Hermansyah via mdaemon-l wrote:


Nah ini dia penyebabnya mail  2020-11-16 11:27:44 s.d 14.00 ditolak.
Cari di smtp-in log 2020-11-16 berkisar jam 10 - 11.18 apakah ada transaksi dari
103.69.140.247 [sinsgout.his.huawei.com] yang ditolak karena kirim mail ke
banyak unknown recipient.


Sepertinya ini log terakhirnya pak,

Mon 2020-11-16 11:18:58.288: 01: --

Mon 2020-11-16 11:18:59.265: 05: [07641866] Session 07641866; child 0004
Mon 2020-11-16 11:18:59.265: 05: [07641866] Accepting SMTP connection 
from 103.69.140.247:35689 to 124.81.84.135:25
Mon 2020-11-16 11:18:59.265: 07: [07641866] Location Screen says 
connection is from Malaysia, Asia
Mon 2020-11-16 11:18:59.266: 03: [07641866] --> 220 mail.persada.id 
ESMTP MDaemon 20.0.1; Mon, 16 Nov 2020 11:18:59 +0700

Mon 2020-11-16 11:18:59.281: 02: [07641866] <-- EHLO sinsgout.his.huawei.com
Mon 2020-11-16 11:18:59.282: 03: [07641866] --> 250-mail.persada.id 
Hello sinsgout.his.huawei.com [103.69.140.247], pleased to meet you

Mon 2020-11-16 11:18:59.282: 03: [07641866] --> 250-ETRN
Mon 2020-11-16 11:18:59.282: 07: [07641866] Location Screening hiding 
AUTH from country Malaysia, Asia

Mon 2020-11-16 11:18:59.282: 03: [07641866] --> 250-8BITMIME
Mon 2020-11-16 11:18:59.282: 03: [07641866] --> 250-ENHANCEDSTATUSCODES
Mon 2020-11-16 11:18:59.282: 03: [07641866] --> 250 SIZE
Mon 2020-11-16 11:18:59.297: 02: [07641866] <-- MAIL 
FROM: SIZE=3077800
Mon 2020-11-16 11:18:59.306: 05: [07641866] Performing PTR lookup 
(247.140.69.103.IN-ADDR.ARPA)
Mon 2020-11-16 11:18:59.308: 05: [07641866] * 
D=247.140.69.103.IN-ADDR.ARPA TTL=(6) PTR=[sinsgout.his.huawei.com]
Mon 2020-11-16 11:18:59.310: 05: [07641866] * D=sinsgout.his.huawei.com 
TTL=(6) A=[103.69.140.247]

Mon 2020-11-16 11:18:59.310: 05: [07641866]  End PTR results
Mon 2020-11-16 11:18:59.312: 05: [07641866] Performing IP lookup 
(sinsgout.his.huawei.com)
Mon 2020-11-16 11:18:59.313: 05: [07641866] * D=sinsgout.his.huawei.com 
TTL=(6) A=[103.69.140.247]

Mon 2020-11-16 11:18:59.313: 05: [07641866]  End IP lookup results
Mon 2020-11-16 11:18:59.319: 05: [07641866] Performing IP lookup 
(huawei.com)
Mon 2020-11-16 11:18:59.321: 05: [07641866] *  D=huawei.com TTL=(6) 
A=[121.37.49.12]
Mon 2020-11-16 11:18:59.322: 05: [07641866] *  P=010 S=001 D=huawei.com 
TTL=(6) MX=[mx5.huawei.com]
Mon 2020-11-16 11:18:59.322: 05: [07641866] *  P=020 S=000 D=huawei.com 
TTL=(6) MX=[mx7.huawei.com]
Mon 2020-11-16 11:18:59.322: 05: [07641866] *  P=030 S=002 D=huawei.com 
TTL=(6) MX=[mx8.his.huawei.com]
Mon 2020-11-16 11:18:59.322: 05: [07641866] *  P=030 S=003 D=huawei.com 
TTL=(6) MX=[mx9.his.huawei.com]
Mon 2020-11-16 11:18:59.324: 05: [07641866] *  D=mx5.huawei.com TTL=(6) 
A=[103.218.216.136]
Mon 2020-11-16 11:18:59.325: 05: [07641866] *  D=mx7.huawei.com TTL=(6) 
A=[168.195.93.46]
Mon 2020-11-16 11:18:59.327: 05: [07641866] *  D=mx8.his.huawei.com 
TTL=(6) A=[103.69.140.246]
Mon 2020-11-16 11:18:59.328: 05: [07641866] *  D=mx9.his.huawei.com 
TTL=(6) A=[185.176.79.54]

Mon 2020-11-16 11:18:59.328: 05: [07641866]  End IP lookup results
Mon 2020-11-16 11:18:59.330: 03: [07641866] --> 250 2.1.0 Sender OK
Mon 2020-11-16 11:18:59.345: 02: [07641866] <-- RCPT 
TO:
Mon 2020-11-16 11:18:59.348: 01: [07641866] Sender attempted to deliver 
message to unknown address
Mon 2020-11-16 11:18:59.348: 03: [07641866] --> 550 5.1.1 Recipient 
unknown 
Mon 2020-11-16 11:18:59.378: 02: [07641866] <-- RCPT 
TO:
Mon 2020-11-16 11:18:59.380: 01: [07641866] Sender attempted to deliver 
message to unknown address
Mon 2020-11-16 11:18:59.380: 03: [07641866] --> 550 5.1.1 Recipient 
unknown 

Mon 2020-11-16 11:18:59.409: 02: [07641866] <-- RCPT TO:
Mon 2020-11-16 11:18:59.411: 01: [07641866] Sender attempted to deliver 
message to unknown address
Mon 2020-11-16 11:18:59.411: 03: [07641866] --> 550 5.1.1 Recipient 
unknown 
Mon 2020-11-16 11:18:59.437: 02: [07641866] <-- RCPT 
TO:
Mon 2020-11-16 11:18:59.439: 01: [07641866] Sender attempted to deliver 
message to unknown address
Mon 2020-11-16 11:18:59.439: 03: [07641866] --> 550 5.1.1 Recipient 
unknown 

Mon 2020-11-16 11:18:59.469: 02: [07641866] <-- RCPT TO:
Mon 2020-11-16 11:18:59.471: 01: [07641866] More than 5 RCPT commands 
encountered; this session tarpitted with a 10 second initial delay 
scaling by 1.00
Mon 2020-11-16 11:18:59.472: 01: [07641866] Sender attempted to deliver 
message to unknown address
Mon 2020-11-16 11:18:59.472: 03: [07641866] --> 550 5.1.1 Recipient 
unknown 
Mon 2020-11-16 11:18:59.583: 01: [07641866] Dynamic screening 
configuration requires closing this session
Mon 2020-11-16 11:18:59.583: 04: [07641866] SMTP session terminated 
(Bytes in/out: 248/505)

Mon 2020-11-16 11:18:59.583: 01: --


Kalau melihat errornya, terindikasi setting SMTP screening terlalu kecil
nilainya, perlu dinaikkan nilainya mengantisipasi sender salah tulis alamat
recipient.

http://mdaemon.dutaint.co.id/mdaemon/20.0/index.html?security--smtp

[mdaemon-l] Connection timed out!

2020-11-17 Terurut Topik Syafril Hermansyah via mdaemon-l


On 17/11/20 15.00, Rievo Niemrod E wrote:
> Mohon pencerahannya hari ini ada beberapa email dari yahoo yang tidak bisa
> masuk ke tempat kami
> 
> Problemnya apa ya Pak kira2 ? 


Yahoo sedang restrukturisasi server-servernya, dari terpusat ke regional.
Tadinya terpusat di yahoo.com menjadi yahoo asia-pacific, yahoo europe dst
sehingga kapasitas kanal internet mereka juga (prioritasnya) berubah.


> lalu untuk solusinya ?


Sarankan ke rekan korespondensi untuk pakai yahoo (regional) asia pacific
(yahoo.co.id, yahoo.com.sg, yahoo.com.ph, yahoo.in, yahoo.co.kr, yahoo.co.jp,
yahoo.com.hk dll) sebagai pengganti yahoo.com/ymail.com/rocketmail.com.

Untuk sementara, bisa hubungi ISP untuk optimasi koneksi internet internasional.


-- 
syafril

Syafril Hermansyah

MDaemon-L Moderator, run MDaemon 20.5.0 64bit Beta B
Mohon tidak kirim private mail (atau cc:) untuk masalah MDaemon.

Bodily exercise, when compulsory, does no harm to the body; but knowledge which
is acquired under compulsion obtains no hold on the mind.
--- Plato, The Republic


-- 
--[mdaemon-l]--
Milis ini untuk Diskusi antar pengguna MDaemon Mail Server di Indonesia

Netiket: https://wiki.openstack.org/wiki/MailingListEtiquette
Arsip: http://mdaemon-l.dutaint.com
Dokumentasi : http://mdaemon.dutaint.co.id
Berlangganan: Kirim mail ke mdaemon-l-subscr...@dutaint.com
Henti Langgan: Kirim mail ke mdaemon-l-unsubscr...@dutaint.com
Versi terakhir: MDaemon 20.0.3, SecurityGateway 7.0.1




[mdaemon-l] Connection timed out!

2020-11-17 Terurut Topik Rievo Niemrod E
Selamat Siang 

 

Dear Pak Syafril 

Mohon pencerahannya hari ini ada beberapa email dari yahoo yang tidak bisa
masuk ke tempat kami 

Problemnya apa ya Pak kira2 ? lalu untuk solusinya ?

 

Mohon bantuannya Pak 

 

Terima Kasih

Rievo

 

Tue 2020-11-17 14:54:36.980: --

Tue 2020-11-17 14:43:11.730: [12671966] Session 12671966; child 0004

Tue 2020-11-17 14:43:11.730: [12671966] Accepting SMTP connection from
66.163.184.148:38794 to 172.16.0.6:25

Tue 2020-11-17 14:43:11.730: [12671966] Location Screen says connection is
from United States, North America

Tue 2020-11-17 14:43:11.731: [12671966] --> 220 bb.ptbmi.com ESMTP MDaemon
20.0.3; Tue, 17 Nov 2020 14:43:11 +0700

Tue 2020-11-17 14:43:12.060: [12671966] <-- EHLO
sonic309-22.consmr.mail.ne1.yahoo.com

Tue 2020-11-17 14:43:12.060: [12671966] --> 250-bb.ptbmi.com Hello
sonic309-22.consmr.mail.ne1.yahoo.com [66.163.184.148], pleased to meet you

Tue 2020-11-17 14:43:12.060: [12671966] --> 250-ETRN

Tue 2020-11-17 14:43:12.060: [12671966] Location Screening hiding AUTH from
country United States, North America

Tue 2020-11-17 14:43:12.060: [12671966] --> 250-8BITMIME

Tue 2020-11-17 14:43:12.060: [12671966] --> 250-ENHANCEDSTATUSCODES

Tue 2020-11-17 14:43:12.060: [12671966] --> 250-STARTTLS

Tue 2020-11-17 14:43:12.060: [12671966] --> 250 SIZE 36700160

Tue 2020-11-17 14:43:20.769: [12671966] <-- MAIL
FROM:

Tue 2020-11-17 14:43:20.774: [12671966] Performing PTR lookup
(148.184.163.66.IN-ADDR.ARPA)

Tue 2020-11-17 14:43:20.815: [12671966] *  D=148.184.163.66.in-addr.arpa
TTL=(30) PTR=[sonic309-22.consmr.mail.ne1.yahoo.com]

Tue 2020-11-17 14:43:21.009: [12671966] *
D=sonic309-22.consmr.mail.ne1.yahoo.com TTL=(30) A=[66.163.184.148]

Tue 2020-11-17 14:43:21.009: [12671966]  End PTR results

Tue 2020-11-17 14:43:21.010: [12671966] Performing IP lookup
(sonic309-22.consmr.mail.ne1.yahoo.com)

Tue 2020-11-17 14:43:21.018: [12671966] *
D=sonic309-22.consmr.mail.ne1.yahoo.com TTL=(30) A=[66.163.184.148]

Tue 2020-11-17 14:43:21.018: [12671966]  End IP lookup results

Tue 2020-11-17 14:43:21.022: [12671966] Performing IP lookup (yahoo.com)

Tue 2020-11-17 14:43:21.031: [12671966] *  D=yahoo.com TTL=(22)
A=[74.6.231.20]

Tue 2020-11-17 14:43:21.031: [12671966] *  D=yahoo.com TTL=(22)
A=[74.6.231.21]

Tue 2020-11-17 14:43:21.031: [12671966] *  D=yahoo.com TTL=(22)
A=[74.6.143.26]

Tue 2020-11-17 14:43:21.031: [12671966] *  D=yahoo.com TTL=(22)
A=[74.6.143.25]

Tue 2020-11-17 14:43:21.031: [12671966] *  D=yahoo.com TTL=(22)
A=[98.137.11.163]

Tue 2020-11-17 14:43:21.031: [12671966] *  D=yahoo.com TTL=(22)
A=[98.137.11.164]

Tue 2020-11-17 14:43:21.038: [12671966] *  P=001 S=000 D=yahoo.com TTL=(20)
MX=[mta5.am0.yahoodns.net]

Tue 2020-11-17 14:43:21.038: [12671966] *  P=001 S=001 D=yahoo.com TTL=(20)
MX=[mta7.am0.yahoodns.net]

Tue 2020-11-17 14:43:21.038: [12671966] *  P=001 S=002 D=yahoo.com TTL=(20)
MX=[mta6.am0.yahoodns.net]

Tue 2020-11-17 14:43:21.250: [12671966] *  D=mta5.am0.yahoodns.net TTL=(1)
A=[67.195.228.111]

Tue 2020-11-17 14:43:21.250: [12671966] *  D=mta5.am0.yahoodns.net TTL=(1)
A=[98.136.96.91]

Tue 2020-11-17 14:43:21.250: [12671966] *  D=mta5.am0.yahoodns.net TTL=(1)
A=[67.195.204.77]

Tue 2020-11-17 14:43:21.250: [12671966] *  D=mta5.am0.yahoodns.net TTL=(1)
A=[67.195.204.79]

Tue 2020-11-17 14:43:21.250: [12671966] *  D=mta5.am0.yahoodns.net TTL=(1)
A=[98.136.96.75]

Tue 2020-11-17 14:43:21.250: [12671966] *  D=mta5.am0.yahoodns.net TTL=(1)
A=[98.136.96.74]

Tue 2020-11-17 14:43:21.250: [12671966] *  D=mta5.am0.yahoodns.net TTL=(1)
A=[67.195.204.73]

Tue 2020-11-17 14:43:21.250: [12671966] *  D=mta5.am0.yahoodns.net TTL=(1)
A=[98.136.96.76]

Tue 2020-11-17 14:43:21.454: [12671966] *  D=mta7.am0.yahoodns.net TTL=(1)
A=[67.195.228.111]

Tue 2020-11-17 14:43:21.454: [12671966] *  D=mta7.am0.yahoodns.net TTL=(1)
A=[98.136.96.74]

Tue 2020-11-17 14:43:21.454: [12671966] *  D=mta7.am0.yahoodns.net TTL=(1)
A=[67.195.204.73]

Tue 2020-11-17 14:43:21.454: [12671966] *  D=mta7.am0.yahoodns.net TTL=(1)
A=[67.195.228.110]

Tue 2020-11-17 14:43:21.454: [12671966] *  D=mta7.am0.yahoodns.net TTL=(1)
A=[67.195.228.94]

Tue 2020-11-17 14:43:21.454: [12671966] *  D=mta7.am0.yahoodns.net TTL=(1)
A=[67.195.204.79]

Tue 2020-11-17 14:43:21.454: [12671966] *  D=mta7.am0.yahoodns.net TTL=(1)
A=[98.136.96.76]

Tue 2020-11-17 14:43:21.454: [12671966] *  D=mta7.am0.yahoodns.net TTL=(1)
A=[98.136.96.77]

Tue 2020-11-17 14:43:21.657: [12671966] *  D=mta6.am0.yahoodns.net TTL=(1)
A=[67.195.228.110]

Tue 2020-11-17 14:43:21.657: [12671966] *  D=mta6.am0.yahoodns.net TTL=(1)
A=[98.136.96.74]

Tue 2020-11-17 14:43:21.657: [12671966] *  D=mta6.am0.yahoodns.net TTL=(1)
A=[67.195.204.77]

Tue 2020-11-17 14:43:21.657: [12671966] *  D=mta6.am0.yahoodns.net TTL=(1)
A=[98.136.96.76]

Tue 2020-11-17 14:43:21.657: [12671966] *  D=mta6.am0.yahoodns.net TTL=(1)
A=[98.136.96.75]

Tue 2020-11-17 14:43:21.657: [12671966] *  D=mta6.am0.yahoodns.net TTL=(1)
A=[67.195.20