On Sun, August 26, 2012 8:35 am, Reindl Harald wrote:

>> is it a 'good idea' to firewall block such when they're from
>
> depends on your business
> i tend to do so at least for some days

Reindl,

so either of the two anvil/IP log lines indicates excess, yes ?

Aug 27 06:00:03 postfix/anvil[4396]: statistics: max connection rate
15/1800s for (smtp:27.115.112.50) at Aug 27 05:59:14
Aug 27 06:00:03 postfix/anvil[4396]: statistics: max connection count 1
for (smtp:27.115.112.50) at Aug 27 05:50:26
Aug 27 06:00:03 postfix/anvil[4396]: statistics: max cache size 51 at Aug
27 05:59:47

you wouldn't happen to have a regex to pick up the offending IP ?

my new Centos came with 'csf' so might try to feed offending IPs to csf
for temp block (if I can figure out regex first)

thanks again
Voytek


Reply via email to