Hi,
Apologies in advance, as I'm not sure if this can be addressed on the UTM or needs to be handled on my Kerio Connect server. Our Kerio server's "directory harvest attack" protection throws up a temporary block on offending IP addresses when a bunch of emails come in from it to unknown addresses. The problem is it sees ALL messages as coming through the UTM, including staff since, like many, we're remote the days. The result is that people stop getting emails for 15 minutes or sometimes hours if more unknown address attempts trickle in before the block times out and it resets
My Kerio log shows things like this:
[15/Apr/2020 11:25:09] Attempt to deliver to unknown recipient <auser@domain.com>, from <>, IP address 192.168.0.1
[15/Apr/2020 11:25:09] Attempt to deliver to unknown recipient <buser@domain.com>, from <>, IP address 192.168.0.1
[15/Apr/2020 11:32:06] Attempt to deliver to unknown recipient <cuser@domain.com>, from <>, IP address 192.168.0.1
[15/Apr/2020 11:32:23] Attempt to deliver to unknown recipient <duser@domain.com>, from <>, IP address 192.168.0.1
[15/Apr/2020 11:32:40] Attempt to deliver to unknown recipient <euser@domain.com>, from <>, IP address 192.168.0.1
[15/Apr/2020 11:33:05] Attempt to deliver to unknown recipient <fuser@domain.com>, from <>, IP address 192.168.0.1
[15/Apr/2020 11:33:24] Attempt to deliver to unknown recipient <guser@domain.com>, from <>, IP address 192.168.0.1
I have Verify with Callout enabled on the UTM, so I'm not sure if that's what's telling the mail server there's a bunch of attempts or if it's not doing what I think and trying to send the email to the server even if the destination address does not exist.
Is there a way have the UTM pass through the originating address? I see "transparent mode" but I've read that should only bee used in very specific circumstances and may apply to outgoing messages only.
For now I've turned off this security feature on my mail server, but we're getting a bunch more spam and will likely get more malware attempts soon.
I'll be posting a similar question to Kerio (GFI) forums as, as I said, I am not sure which, if either, device can do something about it.
Thanks,
Jeff
This thread was automatically locked due to age.