This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall blocking

Hello,

I have added a Network Definitions group called "Blocked Attackers" and added several IP addresses and IP subnets.
I added a firewall rule (on position 1) with the following settings:

Sources: Blocked Attackers
Services: Any
Destinations: Any
Action: Drop (also tried reject)

The rule is enabled but I still see the IP address appear on the SMTP proxy trying to authenticate.

Am I missing something here?



This thread was automatically locked due to age.
Parents Reply
  • Thank you, I did that.

    Seems that the drop is not really working though:

    2018:04:25-15:29:21 mailserver exim-in[31820]: 2018-04-25 15:29:21 SMTP connection from (User) [181.214.206.44]:25680 closed by QUIT

    While I added the subnet 181.214.206.0/24 to the Blocked Attackers group.

Children