Dnia 22.06.2023 o godz. 15:45:43 Allen Coates via Postfix-users pisze: > > Just thinking at a tangent... > > Is it possible / practical to develop the concept of a "service area" - to > white-list all the net-blocks where all your > genuine callers originate, and prohibit everywhere else? > > For myself, I am able to firewall my Submission/IMAP/SSH ports to allow just > the one net-block over the Internet, and to > use an ACL on PostScreen to disallow certain countries which are "nuisances".
If you can be sure that legitimate requests to these services will come only from particular range of addresses, you of course could and maybe even should implement such restriction. From what I know, this is done quite often on servers that can have such well-defined address range for possible clients. Like for example you have an internal company server that nobody outside the company's network should be accessing. -- Regards, Jaroslaw Rafa r...@rafa.eu.org -- "In a million years, when kids go to school, they're gonna know: once there was a Hushpuppy, and she lived with her daddy in the Bathtub." _______________________________________________ Postfix-users mailing list -- postfix-users@postfix.org To unsubscribe send an email to postfix-users-le...@postfix.org