Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 11-21-2009, 02:46 AM
Moderator
 
Posts: 7,911
Default Greylisting and a new approach ?

Recently I have been introduced to Welcome to the Home of OSSEC (which is a great tool) and thought about a different use for it. It already has a decoder/ruleset for Postfix so instead of issuing a iptables block from a command action why not inject the source IP address into a greylisting table ossec already has its own timeout capability which could be used to delete the entry after a pre-determined time.

Thoughts ?
__________________
Reply With Quote
  #2 (permalink)  
Old 11-22-2009, 10:30 PM
Partner (VAR/HSP)
 
Posts: 259
Default

If you are concerned about a host to use OSSEC, then maybe iptables is a better approach. greylisting is not like the same door-slamming effect of simply dropping traffic from a suspect host.
__________________
http://www.solutionsfirst.com.au/hosting/zimbra/
Australia's premier Zimbra Hosting Partner
Resellers wanted!
Reply With Quote
  #3 (permalink)  
Old 11-23-2009, 12:14 AM
Moderator
 
Posts: 7,911
Default

Thanks for the response. I do not wish to "slam the door" but temporarily stem the inbound traffic from a bot or rooted server. I could just run a greyserver and let that apply the rules to all inbound traffic; though I have been burnt by that before. By using the method I have indicated it would only apply greylisting to specific inbound servers. Perhaps apply a 450 for 5 minutes, but keep a track of the IP, and if they connect again within a certain time period steadily increase the greylisting time.
__________________
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.