RE: ISP outbound SMTP filtering
"Kevin Kargel" <kkargel-BvA0c2rBOuxWk0Htik3J/[email protected]>
| Newsgroups | gmane.org.operators.internet-access |
|---|---|
| Message-ID | <70DE64CEFD6E9A4EB7FAF3A063141066706F7D@mail> |
Analysis of network traffic is always good to let you know what is going on, but doing any analysis to the point of being able to differentiate between legitimate traffic and zombies would be extremely difficult. It is pretty much a given that if you do not have defenses in place you will have zombie traffic. Redirection to your mail server is also risky if your mail server allows relay by IP. This would be a pretty sure way to get your mail server on the blacklists. Forcing zombie traffic to your mail server will make your mail server appear spam friendly to the world. If you do silly router tricks to redirect port 25 traffic to your mail server I would suggest implementing SMTP auth to limit the zombie activity. This carries it's own frustrations, as you will need to reconfigure/educate all of your SMTP users. > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of william(at)elan.net > Sent: Wednesday, May 30, 2007 6:00 PM > To: [email protected] > Subject: Re: ISP outbound SMTP filtering > > > If you're dialup/dsl/similar ISP, I recommend outright > blocking of SMTP with exception of those who have > specifically informed you that they need. I would also define > need as someone who runs their own mail server or needs to > connect to outside mail server for sending out email and that > server does not offer submit (port 587). > > Also before doing all this I'd first to do analysis of > traffic on your network (for a day or a week) to find which > ips on your network actually make SMTP connections (outside > of your network) and how often. > That would help quite a bit in deciding if there are going to > be issues with blocking SMTP. Besides that you may find quite > easy to spot and whitelist those who do use SMTP legitimately > and what you might want to do is block all but those ips > first, see who complaints and then start dealing with these cases. > > Also another option to just direct blocking is redirection to > your own mail server by default. You have to think if you > really want those extra connections and related issues or not ... > > On Wed, 30 May 2007, Brian Johnson wrote: > > > > > I have been contemplating our outbound filtering policy and am > > wondering what kind of outbound filters other > regional/local ISPs are using. > > Currently > > we are looking at blocking outbound SMTP to curb botnet spamming > > systems, but would be interested in any "standard" filters that you > > are applying to prevent "bad traffic" from users. > > > > For those of you who have done this, does it work? What issues have > > you had? > > General comments. > > > > For those who don't do this, why? What reasons do you have for not > > doing this? General comments. > > > > TIA. > _______________________________________________ > "Eat sushi frequently". - Avi > [email protected] is the human contact address. > [email protected] is the list posting address. > See below URL for subscribe/unsubscribe and list options: > http://inet-access.net/mailman/listinfo/list > _______________________________________________ "Eat sushi frequently". - Avi [email protected] is the human contact address. [email protected] is the list posting address. See below URL for subscribe/unsubscribe and list options: http://inet-access.net/mailman/listinfo/list