On 30/11/16 11:45, Wietse Venema wrote: > Allen Coates: >> Hello all >> >> From time to time I see a strange log entry: >> >> 2016-11-30T10:40:43+00:00 geronimo postfix/postscreen[20844]: warning: >> getpeername: Transport endpoint is not connected -- dropping this connection > The connection was closed before postscreen could determine the IP > address information. Could be a portscan, some other probing system, > or some other abnormal client. >
I had a hunch that it might be some sort of probe. >> Is there anything I could/should do about it? > On the Internet, shit happens. If you're curious you could run a > network sniffer and find out the source IP address of those > connections. > > Wietse > In my working days, there was an engineering proverb: "If you don't want them to play with knobs and switches, don't give them any". I am a staunch believer in not giving "them" the remotest opportunity to break into - or break - a system. In this case, I think I will content myself with a review of my firewall rules. Many thanks Allen C