On Sun, August 26, 2012 8:35 am, Reindl Harald wrote: >> is it a 'good idea' to firewall block such when they're from > > depends on your business > i tend to do so at least for some days
Reindl, so either of the two anvil/IP log lines indicates excess, yes ? Aug 27 06:00:03 postfix/anvil[4396]: statistics: max connection rate 15/1800s for (smtp:27.115.112.50) at Aug 27 05:59:14 Aug 27 06:00:03 postfix/anvil[4396]: statistics: max connection count 1 for (smtp:27.115.112.50) at Aug 27 05:50:26 Aug 27 06:00:03 postfix/anvil[4396]: statistics: max cache size 51 at Aug 27 05:59:47 you wouldn't happen to have a regex to pick up the offending IP ? my new Centos came with 'csf' so might try to feed offending IPs to csf for temp block (if I can figure out regex first) thanks again Voytek