LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 04-06-2006, 10:51 AM   #1
shawnbishop
Member
 
Registered: Dec 2005
Location: South Africa
Distribution: CentOS,Ubuntu,Fedora
Posts: 249

Rep: Reputation: 30
Postfix client=unknown [192.168.0.78]


Good Day

I am running a postfix server,using a DHCP server to assign addresses.
I have searched all over the web for this info but cant find anything.
In my /var/log/maillog I get the following "errors",does anybody know what it means and whether I should be concerned.

/var/log/maillog

17:26:44 mailserver postfix/qmgr[13406]: 37ECF1A8001: from=<khulani@dubaisa.com>, size=2210, nrcpt=1 (queue active)
Apr 6 17:26:46 mailserver postfix/smtpd[20848]: disconnect from unknown[192.168.0.152]
Apr 6 17:26:51 mailserver postfix/qmgr[13406]: 70B841A8003: from=<Jacquesb.dsa@emaar.ae>, size=6098252, nrcpt=1 (queue active)
Apr 6 17:26:51 mailserver postfix/smtpd[20790]: disconnect from relay.dubaisa.com[196.31.48.202]
Apr 6 17:26:51 mailserver postfix/virtual[20793]: 70B841A8003: to=<tim@dubaisa.com>, relay=virtual, delay=17, status=sent (delivered to maildir)
Apr 6 17:26:51 mailserver postfix/qmgr[13406]: 70B841A8003: removed
Apr 6 17:27:04 mailserver postfix/smtp[20391]: 37ECF1A8001: to=<athij@bentel.net>, relay=mail.bentel.net[196.25.227.131], delay=20, status=sent (250 2.0.0 k36FQkEs014316 Message accepted for delivery)
Apr 6 17:27:04 mailserver postfix/qmgr[13406]: 37ECF1A8001: removed
Apr 6 17:28:52 mailserver postfix/smtpd[20875]: connect from unknown[192.168.0.164]

Kind Regards

Shawn
 
Old 04-06-2006, 11:43 AM   #2
lucktsm
Member
 
Registered: May 2004
Location: Atlanta, GA USA
Distribution: Redhat ES4, FC4, FC5, slax, ubuntu, knoppix
Posts: 155

Rep: Reputation: 30
Shawn,

This is typically a spammer trying to find out if you are an open relay or trying to get the mail recipients of your system. There is a few postfix configurations that will disallow this. You can use this to stop or cut back on the spammers. Put this in your /etc/postfix/main.cf file at the bottom.


### ANTI SPAM MEASURES
#
# The commented lines kills a tad too much
# (kept for educaitonal use)
#
# smtpd_helo_required = yes
smtpd_sender_restrictions = reject_unknown_address
smtpd_recipient_restrictions = permit_sasl_authenticated, reject_non_fqdn_sender,
reject_unknown_sender_domain,
reject_unknown_recipient_domain,
reject_unauth_pipelining,
permit_mynetworks,
reject_unauth_destination,
reject_rbl_client sbl-xbl.spamhaus.org,
reject_rbl_client list.dsbl.org,
reject_rbl_client zombie.dnsbl.sorbs.net,
reject_rbl_client relays.ordb.org
# reject_non_fqdn_recipient,
smtpd_timeout = 90s
smtpd_recipient_limit = 15
smtpd_soft_error_limit = 5
 
Old 04-06-2006, 02:34 PM   #3
shawnbishop
Member
 
Registered: Dec 2005
Location: South Africa
Distribution: CentOS,Ubuntu,Fedora
Posts: 249

Original Poster
Rep: Reputation: 30
Hi Luck

Thanks for the reply,but is this not from within my network as it is a local IP address? (192.168.0.X) is my internal network address.

Thanks

Shawn
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Is someone on my network?! ::ffff:192.168.0.10:ssh ::ffff:192.168.0.:38201 ESTABLISHE ming0 Linux - Security 4 04-12-2005 01:04 AM
192.168.2.1 network with 192.168.0.1? Micro420 Linux - Networking 2 02-27-2005 06:59 AM
Iptables is converting -s 192.168.1.0/8 into 192.0.0.0/8 why !? qwijibow Linux - Security 2 01-26-2005 09:57 AM
What does this mean? 192.168.254.32/24 costasm Linux - Networking 5 12-06-2003 04:57 PM
192.168.0.0/25 ? Firew Linux - Networking 1 04-12-2001 01:02 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 02:43 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration