Re: [exim] Blocking a Class C

Góra strony
Delete this message
Reply to this message
Autor: The Doctor
Data:  
Dla: Evgeniy Berdnikov
CC: exim-users
Temat: Re: [exim] Blocking a Class C
On Thu, Dec 08, 2022 at 10:47:18PM +0300, Evgeniy Berdnikov via Exim-users wrote:
> On Thu, Dec 08, 2022 at 12:22:13PM -0700, The Doctor via Exim-users wrote:
> > On Thu, Dec 08, 2022 at 09:24:19PM +0300, Odhiambo Washington via Exim-users wrote:
> [...]
> > > >>> host in "5.34.207.0/24"? yes (matched "5.34.207.0/24")
> > > >>> host in host_reject_connection? yes (matched "+host_rejects")
> > > LOG: refused connection from [5.34.207.3] (host_reject_connection)
> > > 554 SMTP service not available
> > > root@gw:/usr/home/wash #
> >
> > Still seeing
> >
> > netstat -a | egrep smtp
> > tcp4       0      0 exploreedmonton..smtps 5.34.207.189.26526     SYN_RCVD   
> > tcp4       0      0 comparealbertapo.smtps 5.34.207.190.30872     FIN_WAIT_2 
> > tcp4       0      0 204.209.81.148.smtps   5.34.207.114.57546     FIN_WAIT_2 

>
> Rejection with status code 554 requires established TCP connection.
> Study mainlog to check whether connections are rejected.
>
> However, absense of numerous connections in ESTABLISHED state is a hint
> that rejection works.
>
> If you don't want TCP connections, use packet filtering on kernel level
> instead of Exim's configuration options.


I am surprised that my firewall ACL is not getting this
in a switch!

> --
> Eugene Berdnikov
>
> --
> ## List details at https://lists.exim.org/mailman/listinfo/exim-users
> ## Exim details at http://www.exim.org/
> ## Please use the Wiki with this list - http://wiki.exim.org/


--
Member - Liberal International This is doctor@??? Ici doctor@???
Yahweh, King & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b
Happy Christmas 2022 and Merry New Year 2023 Beware https://mindspring.com