I'm running blackice server (newest version) on a mail
server and using it to block dictionary attacks based
upon the smtp error message.

I am seeing hundreds of servers showing up in blackice
server as a TCP probe to port 25 on the mail server.

I need to know if it's normal for a mail server
talking to my mail server to trigger the probe
message?

Does anyone know how blackice determines that this is
a probe to port 25 rather than normal smtp activity?

Those of you running blackice on a mail server, did
you disable to automatic blocking of these probe
attempts?

Thanks for any help you can offer!


                
__________________________________
Do you Yahoo!?
Yahoo! Mail is new and improved - Check it out!
http://promotions.yahoo.com/new_mail
_______________________________________________
ISSForum mailing list
[EMAIL PROTECTED]

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to 
https://atla-mm1.iss.net/mailman/listinfo/issforum

To contact the ISSForum Moderator, send email to [EMAIL PROTECTED]

The ISSForum mailing list is hosted and managed by Internet Security Systems, 6303 
Barfield Road, Atlanta, Georgia, USA 30328.

Reply via email to