Hey Eric, Cheers, Sebastian
> On 30.04.2014, at 02:52, Eric Shubert <[email protected]> wrote: > > Lately I've notice bunches of spamdyke DENIED_RDNS_MISSING messages, > repetitively from the same IP address, one after another. How stupid is that? > ;) I can say that too. Just went through my logs yesterday and found a total of 1200 rejects from a single IP in a matter of days. > > Has anyone set up fail2ban to block these at the firewall after a certain > number of them is received in a certain time period? I figure this might help > to keep the logs a little cleaner No I have not. To be honest, the load it would cause is insignificant. Cleaner logs would be nice though. > > Which makes me think, won't that distort any spam statistical gathering from > the logs? It sure would affect them. Since nothing is logged anymore in spamdyke you'd have to enable drop logs in fail2ban to know that a connect was spamming and blocked. And then you'd also need logging for future connections being blocked to know they are still trying In all honesty I never use stat tracking. As long as I am not bothered with mails coming through I am happy that things work fine. But with only a handful of users, doing all that tracking is more overhead than useful for me. I have a clean inbox, that's all that matters to me and my users. > > So another question. Does/can fail2ban log rejections so they can be counted > in some manner? If fail2ban does log rejections, is there something which > indicates what type of rejection occurred? It'd be nice to know exactly what > the impact of fail2ban is. (You can't manage what you can't measure.) It does. It shows you which filter rule caught an and what action was done. > > Sorry for my fail2ban ignorance. I really hope to get some time for it some > day. Your help helps. :) Been a while for me too - so take my answers with a grain of salt in it. > > Thanks. > > -- > -Eric 'shubes' > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
