I am seeing an attack on exim port 25, as per:
Code: Select all
2017-06-22 19:43:43 SMTP connection from []:13855 (TCP/IP connection count = 84)
2017-06-22 19:43:43 SMTP connection from []:18356 (TCP/IP connection count = 85)
2017-06-22 19:43:44 SMTP connection from []:55947 (TCP/IP connection count = 86)
2017-06-22 19:43:45 SMTP connection from []:16467 (TCP/IP connection count = 85)
2017-06-22 19:43:49 SMTP connection from []:38681 (TCP/IP connection count = 81)
2017-06-22 19:43:49 SMTP connection from []:10962 (TCP/IP connection count = 82)
2017-06-22 19:43:51 SMTP connection from []:24419 (TCP/IP connection count = 81)
2017-06-22 19:43:51 SMTP connection from []:40620 (TCP/IP connection count = 82)
2017-06-22 19:43:51 SMTP connection from []:29151 (TCP/IP connection count = 82)
2017-06-22 19:43:52 SMTP connection from []:28010 (TCP/IP connection count = 82)
2017-06-22 19:43:52 SMTP connection from []:29605 (TCP/IP connection count = 82)
2017-06-22 19:43:54 SMTP connection from []:46029 (TCP/IP connection count = 79)
2017-06-22 19:43:54 SMTP connection from []:30754 (TCP/IP connection count = 79)
2017-06-22 19:43:54 SMTP connection from []:11094 (TCP/IP connection count = 80)
2017-06-22 19:43:54 SMTP connection from []:43072 (TCP/IP connection count = 81)
2017-06-22 19:43:54 SMTP connection from []:29536 (TCP/IP connection count = 82)
I've enabled "blocklists" and also:
PORTFLOOD = 25;tcp;5;43200
The above does not seem to limit connections on port 25 at all.
Also tried CONNLIMIT = 25 and CT_LIMIT = 25
None of the above seems to do anything to block these.
Anyone seen this before or know of a way to block OR at leat limit the connection?