This isn't tarpitting. This is simply cutting the connection after a set number of ERRs on a single SMTP conversation. The connecting addresses are not cached in any way and if they try to connect again immediately, Imail will happily accept the connection. Unless I misunderstand? Needless to say I won't be removing my Imgate box. Hehe.
Dan -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dev Sent: Thursday, April 28, 2005 12:20 AM To: [email protected] Subject: [IMail Forum] Tarpitting [was] So Since Imail 8.20 is out.. Yep, the Ipswitch implementation of tarpitting does turn out to be nearly as unconfigurable as Dan said. According to the release notes, it can only be enabled and controlled via EDITING THE REGISTRY(!), and even then very little tweaking is possible. \Uh-oh, better fasten seat belt, rant on\ Edit the registry? Edit the freaking registry?!?! Jeezus, it's the year 2005, people!!! What is Ipswitch thinking? Why bother having any administrative interface at all? After two years of requests for this feature, how hard was it to add a single "enable" check box?!?!? And what if we need to release an accidentally tarpitted address on the fly, or customize trigger points and durations to the realities of our traffic, and not Ipswitch's? Sorry, looks like we're SOL. It again highlights the systemic problem with Imail I reluctantly stated two weeks ago: "My biggest complaint about Imail was not the features--it was the half-baked implementation of most of them. It was maddening--enough functionality to be ticked on a feature list, but often inflexible, untweakable and sometimes pathetically unusable." Look, I'm glad that Ipswitch FINALLY has basic tarpitting available--but realize that competing servers now give their customers interfaces like this (attached jpg) to allow adjustments for their network conditions. It also has a separate bypass list (bypass tarpit trigger by domain, IP, or email address). Ipswitch is not going to win old customers back, keep exisiting ones, or gain many new with clueless, half-hearted functionality like this. And what manager actually signed-off that controlling a major feature via regedit was "good enough" in 2005?!? That person cares nothing of quality and should be fired. Clear the cobwebs man, and turn the programmers loose on doing it right!!! I don't want to rain on Ipswitch's new release parade tonight--but I hope the other important new additions in 8.2 have a lot more flexibility and fine-tuning capability than this tarpitting implementation. Unbelievable...requiring registry editing for basic settings in 2005...SHEESH! \unfasten seat belt, remove Nomex, rant off\ :-) Dev Wednesday, April 27, 2005, 1:40:07 PM, you wrote: DH> The thing I was interested in was the Dictionary attack feature that DH> breaks a connection after so many ERRs in a single connection. I DH> guess that isn't configurable, because there's no place in the GUI DH> to set it. Not that I need it, but it is really the thing that DH> Imail needs most IMO, a defense against the dictionary attacks that DH> forced me and many others to put up an IMgate box or use BlackIce or DH> some other method of mitigating the extreme loads that Imail was DH> experiencing when it was dealing with the dictionary attacks on its DH> own. To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
