Dnia 22.06.2023 o godz. 15:45:43 Allen Coates via Postfix-users pisze:
> 
> Just thinking at a tangent...
> 
> Is it possible / practical to develop the concept of a "service area" - to 
> white-list all the net-blocks where all your
> genuine callers originate, and prohibit everywhere else?
> 
> For myself, I am able to firewall my Submission/IMAP/SSH ports to allow just 
> the one net-block over the Internet, and to
> use an ACL on PostScreen to disallow certain countries which are "nuisances".

If you can be sure that legitimate requests to these services will come only
from particular range of addresses, you of course could and maybe even
should implement such restriction. From what I know, this is done quite
often on servers that can have such well-defined address range for possible
clients.

Like for example you have an internal company server that nobody outside the
company's network should be accessing.
-- 
Regards,
   Jaroslaw Rafa
   r...@rafa.eu.org
--
"In a million years, when kids go to school, they're gonna know: once there
was a Hushpuppy, and she lived with her daddy in the Bathtub."
_______________________________________________
Postfix-users mailing list -- postfix-users@postfix.org
To unsubscribe send an email to postfix-users-le...@postfix.org

Reply via email to