Re: spamd fake MX

2008-04-10 Thread andrew fresh
On Thu, Apr 10, 2008 at 02:07:43PM +1000, Rod Whitworth wrote:
 Reality check please.
 
 I see quite a few attempts to access port 25 on boxes that don't have
 externally listening smtpd. They show up in firewall logs.
 
 It is a possibility to let spamd listen (as usual, redirected from 25
 to 8025, or even on 25 itself) and feed the IP over to my real MX using
 the spamd sync capability?
 
 I think so but I may just need a cluebat if there is some reson not to.

http://www.hungryhacker.com/articles/misc/spamd

I have been meaning to set this up, and then sync the IPs to my actual
mail servers so they can be blacklisted.  I just haven't had time.

l8rZ,
-- 
andrew - ICQ# 253198 - Jabber: [EMAIL PROTECTED]

BOFH excuse of the day: high pressure system failure



Re: spamd fake MX

2008-04-09 Thread Daniel Ouellet

Rod Whitworth wrote:

Reality check please.

I see quite a few attempts to access port 25 on boxes that don't have
externally listening smtpd. They show up in firewall logs.

It is a possibility to let spamd listen (as usual, redirected from 25
to 8025, or even on 25 itself) and feed the IP over to my real MX using
the spamd sync capability?

I think so but I may just need a cluebat if there is some reson not to.


I don't see a reason not to do it. I have 4 mail servers sync to each 
others and that works very well if you asked me.


The only thing really to be careful about when lots of spamd sync is 
use, or when you add lots of entry in it is the default limits in the 
table entry of pf.


I also have better results with unicast setup for the sync and you want 
to make sure to put a spamd.key as well in the setup.


Works very nicely for me.

Best

Daniel