LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 09-30-2014, 03:13 PM   #1
jlinkels
LQ Guru
 
Registered: Oct 2003
Location: Bonaire, Leeuwarden
Distribution: Debian /Jessie/Stretch/Sid, Linux Mint DE
Posts: 5,195

Rep: Reputation: 1043Reputation: 1043Reputation: 1043Reputation: 1043Reputation: 1043Reputation: 1043Reputation: 1043Reputation: 1043
Connection denial on mail server authentication error - stupid or smart?


Today I had to work on a network which had lost connection to the mail server of their ISP.

It was not possible to connect to the mail server using telnet:
Code:
telnet mail.myisp.com 25
However, by disconnecting all clients from the network and leaving only my laptop connected to the firewall, I could get a connection:
Code:
jlinkels@aserv:~$ telnet mail.myisp.com 25
Trying 113.114.1.4...
Connected to mail.myisp.com.
Escape character is '^]'.
220 mail.myisp.com ESMTP Sendmail 8.14.4/8.14.4/Debian-2ubuntu2.1 Tue, 30 Sep 2014 13:52:10 -0400; NO SPAM / NO UCE / NO JUNK MAIL
^]
telnet> close
However, after I tried this 4 times in a row the connection timed out again:
Code:
jlinkels@aserv:~$ telnet mail.myisp.com 25
Trying 113.114.1.4...
telnet: Unable to connect to remote host: Connection refused
And after 15 minutes I could get 4 connections again and then a timeout. Not only on port 25, but on all mail related ports, like 110, 143, 587 etc.

Now according to my mail host, this is what happens. When users attempt to send mail without proper SMTP authentication. After 4 invalid attempts, the connection is blocked.

I noticed that this does not only happen after 4 invalid attempts, but also after 4 connections without even trying to authenticate or trying to send mail.

I think it is stupid to deny an IP connection based on authentication failure in an application. Or worse yet, an IP connection is denied even without attempting to do anything. Imagine you can't make an SSH connection because [someone else on the network] performed 3 unsuccesful login attempts.

Basically it means that every device on the network which knows the name of the SMTP server can completely block mail traffic on the network by just doing nothing but connecting.

According to my mail host this rule has greatly reduced spam attempts. Sure, my a**. If he switches off the SMTP server completely it will reduce spam even more.

Is my mail host now smart by implementing this rule or stupid because errors are almost impossible to locate?

jlinkels

Last edited by jlinkels; 09-30-2014 at 03:28 PM.
 
Old 09-30-2014, 10:08 PM   #2
ceyx
Member
 
Registered: May 2009
Location: Fort Langley BC
Distribution: Kubuntu,Free BSD,OSX,Windows
Posts: 342

Rep: Reputation: 59
Quote:
If he switches off the SMTP server completely it will reduce spam even more.
Ha ! That is a good one, and true too.

IMHO the mail host is using an overly aggressive filter, which makes the task of troubleshooting impossible. It is stupid - and example of shooting yourself in the foot.

It is possible, in Postfix for example, to enter a static IP ( or even a dynamic one if it doesn't change much ) as an exception to assist you in the troubleshooting part of it, or just make the exception permanent. Not really fair to dump it all on the client.

Threaten to move your mail service if they do not try to assist you with the exception. They won't be around too long if that kind of stuff continues.

Good Luck !
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
sendmail (Smart Host) authentication with server using certificates chingupt Debian 1 05-07-2013 12:07 AM
Smtp authentication Error in virtual mail server turiyain Linux - Server 1 11-30-2009 11:32 AM
Sendmail: eocket wedge , 504 error , dsn error, mail relay connection error djcs Debian 0 03-03-2009 12:41 AM
Squirrel Mail - ERROR: Connection dropped by IMAP server. Braynid Linux - Software 1 10-01-2008 02:47 AM
Mail Server Authentication via LDAP RKris Linux - Networking 2 02-08-2004 05:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:21 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration