This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SMTP relay blacklist function

Hello Community,

I had a question of understanding.

we see a massive brute force SMTP connections on the external interfaces. So we try to block these brute force networks and hosts from SMTP service and use the function Relaying -> "Host/Network Blacklist". But the connections was not blocked and we see new connections in SMTP log file and SMTP communication, MAIL FROM, RCPT TO .....

In UTM help I found "Host/Network Blacklist - Here you can define hosts and networks that shall be blocked by the SMTP proxy. ...."

My expectation was to block the network/host from all SMTP communication, for example as firewall rule as the country blocking mechanism work too. The manual creation a DNAT and send requests to a fake host works as workaround, also country blocking as sledge hammer.

What is the right scenario for "Host/Network Blacklist"? Or is this function without function?

Thanks for your help & Kind regards,
Michael



This thread was automatically locked due to age.
Parents
  • Hello Michael,

    please give us a screenshot which configuration screen you used for this.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Reply
  • Hello Michael,

    please give us a screenshot which configuration screen you used for this.

    Mit freundlichem Gruß, best regards from Germany,

    Philipp Rusch

    New Vision GmbH, Germany
    Sophos Silver-Partner

    If a post solves your question please use the 'Verify Answer' button.

Children