Hi, as I stated in http://marc.theaimsgroup.com/?t=108515235700004&r=1&w=2 we're having lots of FPs because of large ISPs having most of their dynamic IPs RBL'd as open proxies and the like, since they don't filter ports and lately, most every virus gets you a free open proxy...
Since this server doesn't have to handle direct user connections at all, I was thinking about adding '-notfirsthop' to every eval:check_rbl() and eval:check_rbl_sub(). If I understand correctly, if a message is sent directly from an open proxy to my server, I'd be checking it anyway, but if it properly relays thru another server, then I'd be checking the relaying servers and not the originating one... If the relaying server(s) were open proxyies or open relays, then they should also be RBL'd and they'd be hitting. Is my reasoning and understanding correct? Does anyone think I'm doing something very wrongly by doing this? TIA -- Mariano Absatz El Baby ---------------------------------------------------------- It said, "Insert disk #3," but only two will fit!
