Portal Home > Knowledgebase > Articles Database > vps postfix/smtpd connect from unknown IP address
vps postfix/smtpd connect from unknown IP address
Posted by Altssolution, 08-19-2016, 06:08 AM |
i am newbie in vps and vps hosting, recently i installed a postfix in my server
when i check my mail.log file i seen lot of log files :
Aug 18 03:07:07 vps postfix/smtpd[27260]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27261]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27262]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27263]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27264]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27265]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27266]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27267]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27268]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27269]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27270]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27272]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27271]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27273]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27274]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27275]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27276]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27277]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27278]: connect from unknown[163.125.237.112]
Aug 18 03:07:07 vps postfix/smtpd[27279]: connect from unknown[163.125.237.112]
repeting same ip address the another is just like this
Aug 18 03:07:09 vps postfix/smtpd[27309]: warning: Connection concurrency limit exceeded: 51 from unknown[163.125.237.112] for service smtp
|
Posted by Maple-Hosting, 08-19-2016, 01:29 PM |
Found this for you:
https://codepoets.co.uk/2014/postfix...ownip-address/
Hope it helps
|
Posted by Phil McKerracher, 08-19-2016, 04:14 PM |
Looks like someone from China trying to DoS you.
I would use your firewall to block that particular address, then enable postscreen as described here http://www.postfix.org/POSTSCREEN_README.html
|
Posted by Altssolution, 08-20-2016, 07:25 AM |
Guys Thanks for your help, recently i faced vps 'postfix/smtpd connect from unknown IP address '
my friend Phil McKerracher said it's a Dos attack so i start to study this issue
after my search, i insatlled Fail2ban in my client server and add secure futures
[postfix]
enabled = true
port = smtp,ssmtp
filter = postfix
logpath = /var/log/mail.log
maxretry = 5
i think it will clear my issue,
|
Add to Favourites Print this Article
Also Read