Blackice is reporting hundreds of TCP probes to port
25 on my mail server.  The counts are usually about 3
attempts from the same IP.

Will a mail server verifying an account exists on my
imail server cause this behavior?  Is there ever a
circumstance where it would be normal for a TCP probe
on port 25?

I'm trying to understand if I should let blackice keep
blocking those probes or allow them?  I don't want to
block valid mail servers from delivering to us.

We are still experiencing dictionary attacks at the
moment and I suspect this is all part of the attack
and that normally I wouldn't see a probe to port 25.

Can you experts comment?  Any suggestions or
recommedations would as always be most appreciated!


        
                
__________________________________
Do you Yahoo!?
New and Improved Yahoo! Mail - 100MB free storage!
http://promotions.yahoo.com/new_mail 

To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to