Hi!

"The minimum amount of time that postscreen(8) will use the result from a 
successful DNS-based reputation test before a client IP address is required to 
pass that test again."

By "successful" ...

1 - Do you mean that postscreen was able to successfully get any data from a 
dnsbl query - whatever the result was (good or bad reputation)?
2 - Or do you mean that postscreen did get a positive result with (only) good 
reputation from dnsbl?

If 2, is there a way to prevent postscreen from asking dnsbl lists again within 
an amount of time, means cache (or ttl) for some time the result or the decided 
blacklist action for the connecting host, whatever the result was (good or bad)?
We would like to cache the result - whatever it was - for an hour, because some 
hosts seem to try again every few minutes or even seconds.  Would 
"postscreen_dnsbl_min_ttl" be the right way?  If not, what would be the right 
way?  Only Fail2ban?

Thanks,
-lutzn



_______________________________________________
Postfix-users mailing list -- postfix-users@postfix.org
To unsubscribe send an email to postfix-users-le...@postfix.org

Reply via email to