Old 07-28-2011, 11:54 AM   #1 (permalink)
Untanglit
 
Join Date: Mar 2011
Posts: 19
electricus is on a distinguished road
Default rule to block large amounts of inbound port 25 traffic

it sure would be nice to have some way to detect a lot of smtp traffic (spammers) and block those ip's. Is there such a rule in untangle's intrusion prevention module to do that? We only have 6 users here and so we don't have a lot of mail traffic. I would think that there would be a way to detect that kind of network activity and automate blocking ip's of spammers trying to send spam emails through my mail server. Otherwise, I'm just going to have to continue to watch my mail server queue and block ip's manually.
electricus is offline  
Old 07-28-2011, 11:59 AM   #2 (permalink)
Untangle Ninja
 
sky-knight's Avatar
 
Join Date: Apr 2008
Location: Phoenix, AZ
URLs submitted: 8
Posts: 15,457
sky-knight is on a distinguished road
Default

Enable tarpitting.
__________________
Rob Sandling, BS:SWE, MCP
Intouch Technology
Phone: 480-272-9889
rob@intouchtechllc.com

UntangleAppliances.com
Phone: 866-794-8879
sky-knight is offline  
Old 07-28-2011, 12:02 PM   #3 (permalink)
Untanglit
 
Join Date: Mar 2011
Posts: 19
electricus is on a distinguished road
Default

I do have that enabled and it works great. The only drawback is that the ip's must be on the blacklist. That's why I would like to manually create this kind of rule.
electricus is offline  
Old 07-28-2011, 12:13 PM   #4 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,612
dmorris is on a distinguished road
Default

In that case firewall rules will do the trick.

Personally, I think you are asking for trouble. Just because an IP relayed a spam message to you doesn't necessarily mean they are a spammer.

The sole purpose of the "blacklist" you refer to that you don't like is to track the IP of known spammers.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Old 07-28-2011, 12:14 PM   #5 (permalink)
Untanglit
 
Join Date: Mar 2011
Posts: 19
electricus is on a distinguished road
Default

do you know of a website where people have shared common firewall rulesets in .json format to cut down on spam? I could just import it into untangle. Surely people have gotten really good at this sort of thing out there.
electricus is offline  
Old 07-28-2011, 12:18 PM   #6 (permalink)
Master Untangler
 
Big D's Avatar
 
Join Date: Nov 2008
Posts: 691
Big D is on a distinguished road
Default

indead I still like how a client we had tried to send 7000 emails through hosted exchange via rackspace.

Rackspace shut down their account sent them a nasty email and said keep doing that and we'll disable your whole domain email.

But the point being their mailserver would have been relaying out rackspaces relay servers which might have 1000's of legit organizations using it.

Protocol module I haven't personally messed so not sure if it can trigger based on frequency on connections or not.
__________________
The beatings shall continue until morale improves!
Big D is offline  
Old 07-28-2011, 12:19 PM   #7 (permalink)
Untangle Junkie
 
dmorris's Avatar
 
Join Date: Nov 2006
Location: San Mateo, CA
URLs submitted: 10
Posts: 10,612
dmorris is on a distinguished road
Default

Quote:
Originally Posted by electricus View Post
do you know of a website where people have shared common firewall rulesets in .json format to cut down on spam? I could just import it into untangle. Surely people have gotten really good at this sort of thing out there.
I would suggest this one:

http://www.spamhaus.org/

Have fun reinventing the wheel.
__________________
Attention: Support and help on the Untangle Forums is provided by
volunteers and community members like yourself.
If you need Untangle support please call or email support@untangle.com
dmorris is offline  
Closed Thread

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:24 AM.


© 2010 Untangle, Inc. All Rights Reserved.   SEO by vBSEO 3.6.0 PL2