LF_EXIMSYNTAX and LF_IMAPD ignoring blocks
Posted: 13 Jun 2016, 20:01
In the server I have set:
RESTRICT_SYSLOG = 3
LF_TRIGGER = 0
LF_TRIGGER_PERM = 1
LF_SELECT = OFF
LF_EXIMSYNTAX = 10
LF_EXIMSYNTAX_PERM = 3600
LF_IMAPD = 10
LF_IMAPD_PERM = 1
But even with that set, /var/log/messages shows, please note that I don't have those IP white listed:
EXIM SYNTAX, ignored:
Jun 13 12:23:07 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:25:18 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:26:19 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:27:20 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:27:20 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:29:01 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:31:38 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:32:38 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:33:39 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:33:39 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:34:49 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:37:06 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:38:12 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:39:12 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
* SPOOFED IP
IMAPD, ignored:
Jun 13 12:11:23 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:11:28 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:11:28 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:12:33 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:12:43 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:17:32 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:17:47 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:22:37 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:22:52 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:33:39 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:33:49 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:34:49 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:35:00 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:51:19 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:51:30 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
* SPOOFED IPs
This has been working before.
Regards,
Sergio
RESTRICT_SYSLOG = 3
LF_TRIGGER = 0
LF_TRIGGER_PERM = 1
LF_SELECT = OFF
LF_EXIMSYNTAX = 10
LF_EXIMSYNTAX_PERM = 3600
LF_IMAPD = 10
LF_IMAPD_PERM = 1
But even with that set, /var/log/messages shows, please note that I don't have those IP white listed:
EXIM SYNTAX, ignored:
Jun 13 12:23:07 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:25:18 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:26:19 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:27:20 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:27:20 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:29:01 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:31:38 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:32:38 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:33:39 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:33:39 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:34:49 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:37:06 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:38:12 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
Jun 13 12:39:12 serverX lfd[393306]: Exim syntax errors from 123.123.123.123 - ignored
* SPOOFED IP
IMAPD, ignored:
Jun 13 12:11:23 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:11:28 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:11:28 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:12:33 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:12:43 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:17:32 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:17:47 server2 lfd[811449]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:22:37 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:22:52 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:33:39 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:33:49 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:34:49 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:35:00 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:51:19 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
Jun 13 12:51:30 server2 lfd[393306]: Failed IMAP login from 123.123.123.123 - ignored
* SPOOFED IPs
This has been working before.
Regards,
Sergio