This isn't tarpitting.  This is simply cutting the connection after a
set number of ERRs on a single SMTP conversation.  The connecting
addresses are not cached in any way and if they try to connect again
immediately, Imail will happily accept the connection.  Unless I
misunderstand?  Needless to say I won't be removing my Imgate box.
Hehe.

Dan 

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Dev
Sent: Thursday, April 28, 2005 12:20 AM
To: [email protected]
Subject: [IMail Forum] Tarpitting [was] So Since Imail 8.20 is out..

Yep, the Ipswitch implementation of tarpitting does turn out to be
nearly as unconfigurable as Dan said.
According to the release notes, it can only be enabled and controlled
via EDITING THE REGISTRY(!), and even then very little tweaking is
possible.

\Uh-oh, better fasten seat belt, rant on\

Edit the registry? Edit the freaking registry?!?!
Jeezus, it's the year 2005, people!!!

What is Ipswitch thinking? Why bother having any administrative
interface at all? After two years of requests for this feature, how hard
was it to add a single "enable" check box?!?!?

And what if we need to release an accidentally tarpitted address on the
fly, or customize trigger points and durations to the realities of our
traffic, and not Ipswitch's? Sorry, looks like we're SOL.

It again highlights the systemic problem with Imail I reluctantly stated
two weeks ago:

"My biggest complaint about Imail was not the features--it was the
half-baked implementation of most of them. It was maddening--enough
functionality to be ticked on a feature list, but often inflexible,
untweakable and sometimes pathetically unusable."

Look, I'm glad that Ipswitch FINALLY has basic tarpitting available--but
realize that competing servers now give their customers interfaces like
this (attached jpg) to allow adjustments for their network conditions.
It also has a separate bypass list (bypass tarpit trigger by domain, IP,
or email address).

Ipswitch is not going to win old customers back, keep exisiting ones, or
gain many new with clueless, half-hearted functionality like this. And
what manager actually signed-off that controlling a major feature via
regedit was "good enough" in 2005?!? That person cares nothing of
quality and should be fired. Clear the cobwebs man, and turn the
programmers loose on doing it right!!!

I don't want to rain on Ipswitch's new release parade tonight--but I
hope the other important new additions in 8.2 have a lot more
flexibility and fine-tuning capability than this tarpitting
implementation.

Unbelievable...requiring registry editing for basic settings in
2005...SHEESH!

\unfasten seat belt, remove Nomex, rant off\  :-)

Dev


Wednesday, April 27, 2005, 1:40:07 PM, you wrote:

DH> The thing I was interested in was the Dictionary attack feature that

DH> breaks a connection after so many ERRs in a single connection.  I 
DH> guess that isn't configurable, because there's no place in the GUI 
DH> to set it.  Not that I need it, but it is really the thing that 
DH> Imail needs most IMO, a defense against the dictionary attacks that 
DH> forced me and many others to put up an IMgate box or use BlackIce or

DH> some other method of mitigating the extreme loads that Imail was 
DH> experiencing when it was dealing with the dictionary attacks on its 
DH> own.

To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to