Block certain remote hosts on submission port

2013-08-22 Thread Charles Marcus
Hi all, This isn't about spam, this is about blocking obvious attempts to hack/connect to my submission port. I know and understand the argument against just blanket blocking hosts based on the country of origin, but I've recently been seeing random connections on my submission port from

Re: Block certain remote hosts on submission port

2013-08-22 Thread Simon B
On 22 Aug 2013 13:52, Charles Marcus cmar...@media-brokers.com wrote: Hi all, This isn't about spam, this is about blocking obvious attempts to hack/connect to my submission port. I know and understand the argument against just blanket blocking hosts based on the country of origin, but I've

Re: Block certain remote hosts on submission port

2013-08-22 Thread Charles Marcus
On 2013-08-22 8:03 AM, Simon B simon.buongio...@gmail.com wrote: Surely the simplest solution is fail2ban with the false attempts in x minutes resulting in a 20 minute ban? No for two reasons... 1. Again, we have ZERO users who are outside the US, so why allow connections at all? and

Re: Block certain remote hosts on submission port

2013-08-22 Thread li...@rhsoft.net
Am 22.08.2013 14:23, schrieb Charles Marcus: Now to figure out how to log these firewall rejections to a separate log file, so I can see them if/when someone complains about not being able to connect nothing easier than that * the first rule logs with rate-control to avoid self-DOS * the

Filtering outgoing email

2013-08-22 Thread Roman Gelfand
When an outgoing email's target address is prefixed by '+', I would like postfix to delete it replying back to the client ok status. I had previously setup below. But this sends back to the client 554. I would like the client to think that in this situation everything is fine. main.cf

Re: Block certain remote hosts on submission port

2013-08-22 Thread Stan Hoeppner
On 8/22/2013 6:51 AM, Charles Marcus wrote: The simple fact is, we do not have any users based *anywhere* but the US, so, is what is the simplest way to block any/all non-US based client connections on my submission port? Use the us.zone ipdeny file to build a CIDR table to accept any US

Re: Filtering outgoing email

2013-08-22 Thread Drizzt
When an outgoing email's target address is prefixed by '+', I would like postfix to delete it replying back to the client ok status. I had previously setup below. But this sends back to the client 554. I would like the client to think that in this situation everything is fine. main.cf

What are the LDAP config diffs between 2.2.10 and 2.10.1

2013-08-22 Thread Rob Tanner
I am upgrading from 2.2.10 to the current 2.10.1 primarily because the former does not understand milters and we are trying to implement DKIM. The problem is that LDAP appears to be broken and we make extensive use of LDAP. When I first copied the production main.cf over to my development box

Re: What are the LDAP config diffs between 2.2.10 and 2.10.1

2013-08-22 Thread Wietse Venema
Rob Tanner: I am upgrading from 2.2.10 to the current 2.10.1 primarily because the former does not understand milters and we are trying to implement DKIM. The problem is that LDAP appears to be broken and we make extensive use of LDAP. When I first copied the production main.cf over to my

piping bounce service to external program

2013-08-22 Thread Brian Armstrong
I am trying to set up postfix to send bounced messages to an external script to log the bounce to an external logging service so that we can monitor bounce rates to different recipient domains. I want to keep the default bounce behavior intact, so bounce notices are still send to the original

Re: piping bounce service to external program

2013-08-22 Thread Wietse Venema
Brian Armstrong: I am trying to set up postfix to send bounced messages to an external script to log the bounce to an external logging service so that we can monitor bounce rates to different recipient domains. I want to keep the default bounce behavior intact, so bounce notices are still send

Re: Filtering outgoing email

2013-08-22 Thread Roman Gelfand
Thanks a lot. Exactly what I was looking for. On Thu, Aug 22, 2013 at 1:43 PM, Drizzt dri...@wizzard.sinners.be wrote: When an outgoing email's target address is prefixed by '+', I would like postfix to delete it replying back to the client ok status. I had previously setup below. But this

Re: piping bounce service to external program

2013-08-22 Thread Brian Armstrong
Wietse, Thank you very much for your response. I'd mentioned that I'd tried this approach in my first message. You are, however, correct. I was misreading the maillog when I thought it was sending the message and well as hitting my script. I need to look at the daemon/queue/service that is

Re: Block certain remote hosts on submission port

2013-08-22 Thread Stan Hoeppner
On 8/22/2013 9:57 AM, Stan Hoeppner wrote: On 8/22/2013 6:51 AM, Charles Marcus wrote: The simple fact is, we do not have any users based *anywhere* but the US, so, is what is the simplest way to block any/all non-US based client connections on my submission port? Use the us.zone ipdeny

Recipient address rejected: aol.com

2013-08-22 Thread Grant
Does this mean the email address doesn't exist? exam...@aol.com: host mailin-04.mx.aol.com[64.12.138.161] said: 550 5.1.1 exam...@aol.com: Recipient address rejected: aol.com (in reply to RCPT TO command) - Grant