Hello Community,
I had a question of understanding.
we see a massive brute force SMTP connections on the external interfaces. So we try to block these brute force networks and hosts from SMTP service and use the function Relaying -> "Host/Network Blacklist". But the connections was not blocked and we see new connections in SMTP log file and SMTP communication, MAIL FROM, RCPT TO .....
In UTM help I found "Host/Network Blacklist - Here you can define hosts and networks that shall be blocked by the SMTP proxy. ...."
My expectation was to block the network/host from all SMTP communication, for example as firewall rule as the country blocking mechanism work too. The manual creation a DNAT and send requests to a fake host works as workaround, also country blocking as sledge hammer.
What is the right scenario for "Host/Network Blacklist"? Or is this function without function?
Thanks for your help & Kind regards,
Michael
This thread was automatically locked due to age.