Hello guys ,
I have been in the current story before ,
The systems randomaly not bloking black list ip ,
Please look at the following log ....
This Ip : 45.80.175.52 shuld be blocked but got an PASS NEW
After 2 min or so we have this : postfix/postscreen[15796]: PASS OLD [45.80.175.52]:54770
Can someone please explain where am I wrong or what I need to do.
Then you all for any help.
Koby Peleg Hen
Here is my full pmg postconf as an attchment file
I have been in the current story before ,
The systems randomaly not bloking black list ip ,
Please look at the following log ....
This Ip : 45.80.175.52 shuld be blocked but got an PASS NEW
After 2 min or so we have this : postfix/postscreen[15796]: PASS OLD [45.80.175.52]:54770
Can someone please explain where am I wrong or what I need to do.
Then you all for any help.
Koby Peleg Hen
Code:
Oct 17 00:53:20 smg01 postfix/postscreen[15754]: CONNECT from [45.80.175.52]:7302 to [207.154.215.33]:25
Oct 17 00:53:20 smg01 postfix/dnsblog[15763]: addr 45.80.175.52 listed by domain b.barracudacentral.org as 127.0.0.2
Oct 17 00:53:26 smg01 postfix/postscreen[15754]: PASS NEW [45.80.175.52]:7302
Oct 17 00:53:26 smg01 postfix/smtpd[15769]: connect from unknown[45.80.175.52]
Oct 17 00:53:27 smg01 postfix/smtpd[15769]: NOQUEUE: client=unknown[45.80.175.52]
Oct 17 00:53:28 smg01 postfix/smtpd[15769]: NOQUEUE: client=unknown[45.80.175.52]
Oct 17 00:53:30 smg01 postfix/smtpd[15769]: disconnect from unknown[45.80.175.52] ehlo=1 mail=2 rcpt=2 data=2 quit=1 commands=8
Oct 17 00:55:12 smg01 postfix/postscreen[15796]: CONNECT from [45.80.175.52]:54770 to [207.154.215.33]:25
Oct 17 00:55:12 smg01 postfix/postscreen[15796]: PASS OLD [45.80.175.52]:54770
Oct 17 00:55:12 smg01 postfix/smtpd[15797]: connect from unknown[45.80.175.52]
Oct 17 00:55:13 smg01 postfix/smtpd[15797]: NOQUEUE: client=unknown[45.80.175.52]
Oct 17 00:55:14 smg01 postfix/smtpd[15797]: disconnect from unknown[45.80.175.52] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
Oct 17 00:58:34 smg01 postfix/anvil[15771]: statistics: max connection rate 1/60s for (smtpd:45.80.175.52) at Oct 17 00:53:26
Oct 17 00:58:34 smg01 postfix/anvil[15771]: statistics: max connection count 1 for (smtpd:45.80.175.52) at Oct 17 00:53:26
Oct 17 01:22:00 smg01 postfix/postscreen[16064]: CONNECT from [45.80.175.53]:8695 to [207.154.215.33]:25
Oct 17 01:22:01 smg01 postfix/dnsblog[16066]: addr 45.80.175.53 listed by domain b.barracudacentral.org as 127.0.0.2
Oct 17 01:22:06 smg01 postfix/postscreen[16064]: PASS NEW [45.80.175.53]:8695
Oct 17 01:22:06 smg01 postfix/smtpd[16074]: connect from unknown[45.80.175.53]
Oct 17 01:22:06 smg01 postfix/smtpd[16074]: NOQUEUE: client=unknown[45.80.175.53]
Oct 17 01:22:09 smg01 postfix/smtpd[16074]: NOQUEUE: client=unknown[45.80.175.53]
Oct 17 01:22:11 smg01 postfix/smtpd[16084]: B8F07611BF: client=ip6-localhost[127.0.0.1], orig_client=unknown[45.80.175.53]
Oct 17 01:22:13 smg01 postfix/smtpd[16074]: disconnect from unknown[45.80.175.53] ehlo=1 mail=2 rcpt=2 data=1/2 rset=1 quit=1 commands=8/9
Oct 17 01:23:57 smg01 postfix/postscreen[16064]: CONNECT from [45.80.175.53]:52680 to [207.154.215.33]:25
Oct 17 01:23:57 smg01 postfix/postscreen[16064]: PASS OLD [45.80.175.53]:52680
Oct 17 01:23:57 smg01 postfix/smtpd[16096]: connect from unknown[45.80.175.53]
Oct 17 01:23:58 smg01 postfix/smtpd[16096]: NOQUEUE: client=unknown[45.80.175.53]
Oct 17 01:23:59 smg01 postfix/smtpd[16104]: B1C00611BF: client=ip6-localhost[127.0.0.1], orig_client=unknown[45.80.175.53]
Oct 17 01:23:59 smg01 postfix/smtpd[16096]: disconnect from unknown[45.80.175.53] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
Oct 17 01:27:20 smg01 postfix/anvil[16076]: statistics: max connection rate 1/60s for (smtpd:45.80.175.53) at Oct 17 01:22:06
Oct 17 01:27:20 smg01 postfix/anvil[16076]: statistics: max connection count 1 for (smtpd:45.80.175.53) at Oct 17 01:22:06
Oct 17 01:52:01 smg01 postfix/postscreen[16299]: CONNECT from [45.80.175.54]:2620 to [207.154.215.33]:25
Oct 17 01:52:01 smg01 postfix/dnsblog[16304]: addr 45.80.175.54 listed by domain b.barracudacentral.org as 127.0.0.2
Oct 17 01:52:07 smg01 postfix/postscreen[16299]: PASS NEW [45.80.175.54]:2620
Oct 17 01:52:07 smg01 postfix/smtpd[16315]: connect from unknown[45.80.175.54]
Oct 17 01:52:08 smg01 postfix/smtpd[16315]: NOQUEUE: client=unknown[45.80.175.54]
Oct 17 01:52:09 smg01 postfix/smtpd[16315]: NOQUEUE: client=unknown[45.80.175.54]
Oct 17 01:52:11 smg01 postfix/smtpd[16315]: disconnect from unknown[45.80.175.54] ehlo=1 mail=2 rcpt=2 data=2 quit=1 commands=8
Oct 17 01:53:52 smg01 postfix/postscreen[16299]: CONNECT from [45.80.175.54]:53009 to [207.154.215.33]:25
Oct 17 01:53:52 smg01 postfix/postscreen[16299]: PASS OLD [45.80.175.54]:53009
Here is my full pmg postconf as an attchment file