Re: ISP outbound SMTP filtering
JC Dill <[email protected]>
| Newsgroups | gmane.org.operators.internet-access |
|---|---|
| Message-ID | <[email protected]> |
Kevin Kargel wrote:
> Analysis of network traffic is always good to let you know what is going
> on, but doing any analysis to the point of being able to differentiate
> between legitimate traffic and zombies would be extremely difficult.
Huh? Very few non-business ISP customers run SMTP servers. So very few
of them have any reason to be making multiple port 25 connections from
their computer to numerous other computers on the internet. Some users
will have legitimate reasons to connect to port 25 to other servers
(sending mail thru other networks where they have an account, such as
the work server, or their webhost server, or their alternate email
provider) but most of those connections are over port 587 today. Any
computer (especially one on a dynamic IP) that is making multiple
outbound port 25 connections to other computers should be suspected of
being part of a spam-spewing botnet.
> It
> is pretty much a given that if you do not have defenses in place you
> will have zombie traffic.
Very true. So put in the defenses!
> Redirection to your mail server is also risky if your mail server allows
> relay by IP. This would be a pretty sure way to get your mail server on
> the blacklists. Forcing zombie traffic to your mail server will make
> your mail server appear spam friendly to the world.
And what is the problem with that? Said network IS spam-friendly when
you let your customer's zombies run unfettered! If you force those
zombies thru your mail server, then YOU will notice them, then YOU will
get them off the 'net. Those zombies are YOUR responsibility!
> If you do silly router tricks to redirect port 25 traffic to your mail
> server I would suggest implementing SMTP auth to limit the zombie
> activity. This carries it's own frustrations, as you will need to
> reconfigure/educate all of your SMTP users.
Haven't we heard this tired old song ("It's too hard") many times before
as network "best practices" change over time? (e.g. closing open
relays) Yes, you will have to educate your SMTP users. The alternative
is continuing to spew spam. Let's see, on one hand we have zombies on
the network spewing spam, and on the other hand we have educated
customers using SMTP auth and not spewing spam... think, think, think.
Which one is better for the network, better for the internet???
jc
_______________________________________________
"Eat sushi frequently". - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list