Re: ISP outbound SMTP filtering
Herb Peyerl <[email protected]>
| Newsgroups | gmane.org.operators.internet-access |
|---|---|
| Message-ID | <[email protected]> |
On Jun 4, 2007, at 10:20 PM, Blake Pfankuch wrote: > I can see the point of this, but I must agree. Having been one of > those > people who ran a mail server from a business class DSL line who had to > fight for many weeks to get my isp to stop filtering all traffic on > port > 25 I my network very simply. It's in the contract you sign. I filter > nothing, unless specifically requested to do so. I state that it is > your responsibility to make sure that your machine is not a menace > to my > business. I do have guides available to all my customers on how to > make > sure their machine is not spewing filth, and I have in there to > contact > me if you have questions. I help people learn when they compensate > for > my time. I have said that if your computer begins to affect my > network, > I will let you know. After your first warning you have 48 hours to > correct the situation, or I will disable your service until it is > fixed. > I have had to do this once, and the customer didn't fight me on it at > all. That's awfully lenient. If one of your customers is spewing spam at a rate of 1000 messages per hour, 48 hours is an eternity. Also, business class DSL is different. Typically business class customers pay more, sign contracts, and accept a certain amount of liability. Joe's grandma at home is a different story. The average linux weenie trying to operate a mail server in his kitchen cupboard should be relaying his outbound mail through his ISP or through some other third party mail server. He's not going to get much traction on a dynamic address that's in some RBL... I'm all about helping people to learn, but you people are ISP's. You are supposed to be a paragon of responsible netizen. You are not supposed to let spam emanate from your network. Look, this just isn't difficult. In this city, we have 2 primary ISP's. The incumbent telco and the incumbent cableco. There are a few (one less now, as of recently) smaller ISPs who either offer dialup or resell the telco's DSL. The incumbent telco blocks outbound port 25 for residential customers. The cableco doesn't at present but will be in the next 6 months. This is a city of just over 1 million people. The telco isn't out of business and the cableco doesn't seem to have the lions share of their business. People accepted the limitation and got over it. > Like I stated, having fought with my first ISP who was filtering > outbound and incoming traffic, I find it appalling that anyone would > suggest this. I am all about teaching people and helping people > learn. > I would rather run the slight risk that a client could become host to > zombie that spews out thousands of messages a minute, than have a > client > come to me and say "hey why is such and such port filtered." I offer You'd rather force a huge spam problem on the rest of the world than answer a simple question for your customer? >> If I were your customer and you tried to tell me that a standard >> email >> client will not work on your ISP my response would be to find another >> ISP. > > Completely agree. If my current ISP did that and refused to > resolve it > within 72 hours, by then it would be costing me a serious amount of > business. I LIVE by email, and sadly would be completely lost without At no point did I suggest that no one run a standard mail client. That is someone else's rhetoric and apparently neither of you read english all that well. > it. I think as net admins its our job to make things easy for the > client. Not to put on our holier than thou cap and try to protect > the > world from our clients who don't know what they are doing. Again im Well, you are wrong. As a net admin, it is your responsibility to ensure that your network is not a menace to the rest of the world. If you choose to let your customers have outbound port 25 with no restrictions, then it is your subsesquent responsibility to ensure that none of your customers are sending spam on that port. I don't care how you do it, but that is your contract with the world. You have another contract with the world, don't let your routes flap. If they do, you get attenuated until you fix it. You accept that and know it as a fundamental truth. Why is it not likewise with spam? Is it because, at present, the world doesn't have an RBL with your name in it? In May 2006, there was a 20 billion message spam run. 80% of the spam came from windows zombies. (Jason Steer, IronPort). That was from ISP's like you who don't care to run a network correctly. Like I say, I don't care how you get it done, but this is your job, do it. > huge on the education thing, so teach them the value of a good secure > password, teach them not to click on banner ads to "remove spyware", > teach them not to open unsafe attachments and the value of a current > anti-virus subscription (or equivalent free client). Oh please. Spare me the blue skies. While you're in there teaching them, teach them how to configure their mail client to send mail to you using auth with TLS on port 587. > My personal domain is very busy considering there are 3 people with > email accounts. According to my mail server there were 508 > successfully > authenticated messages sent yesterday, and 1126 received. If my isp > said "oh sorry you can only send or receive 500 messages a day I would > be furious. Again, you're reading into what I said. I was talking about how many messages a person can send in some period of time. I don't care how many messages you receive. Completely uninteresting to me. And I didn't say "500 messages a day". What limits you establish are between you and your customer. Remember, you're all about education. You must spend a great deal of your life being 'furious', given that you so consistently misread what people say... People like you two are exactly why we have a spam problem these days. _______________________________________________ "Eat sushi frequently". - Avi [email protected] is the human contact address. [email protected] is the list posting address. See below URL for subscribe/unsubscribe and list options: http://inet-access.net/mailman/listinfo/list