Blackice is reporting hundreds of TCP probes to port
25 on my mail server. The counts are usually about 3
attempts from the same IP.
Will a mail server verifying an account exists on my
imail server cause this behavior? Is there ever a
circumstance where it would be normal for a TCP probe
on port 25?
I'm trying to understand if I should let blackice keep
blocking those probes or allow them? I don't want to
block valid mail servers from delivering to us.
We are still experiencing dictionary attacks at the
moment and I suspect this is all part of the attack
and that normally I wouldn't see a probe to port 25.
Can you experts comment? Any suggestions or
recommedations would as always be most appreciated!
__________________________________
Do you Yahoo!?
New and Improved Yahoo! Mail - 100MB free storage!
http://promotions.yahoo.com/new_mail
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/