This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SMTP relay blacklist function

Hello Community,

I had a question of understanding.

we see a massive brute force SMTP connections on the external interfaces. So we try to block these brute force networks and hosts from SMTP service and use the function Relaying -> "Host/Network Blacklist". But the connections was not blocked and we see new connections in SMTP log file and SMTP communication, MAIL FROM, RCPT TO .....

In UTM help I found "Host/Network Blacklist - Here you can define hosts and networks that shall be blocked by the SMTP proxy. ...."

My expectation was to block the network/host from all SMTP communication, for example as firewall rule as the country blocking mechanism work too. The manual creation a DNAT and send requests to a fake host works as workaround, also country blocking as sledge hammer.

What is the right scenario for "Host/Network Blacklist"? Or is this function without function?

Thanks for your help & Kind regards,
Michael



This thread was automatically locked due to age.
Parents Reply Children
No Data