Topic: postscreen filter fail2ban optimization help
- iRedMail 1.1 openldap edition
- downloadable installer
- Debian GNU/Linux 10 (buster)
- backend (LDAP)
- Web server (Nginx)
I have too many postsreen msg (automated bots), see below, please. I do not know, how to optimize it better.
I have added this filter to fail2ban jail postfix-iredmail:
failregex = postfix.postscreen.* DNSBL .* for \[<HOST>\]:
here is log:
--------------------- Postfix Begin ------------------------
30 Miscellaneous warnings 30
260 Rejected 100.00%
-------- --------------------------------------------------
260 Total 100.00%
======== ==================================================
140 5xx Reject relay denied 53.85%
63 5xx Reject HELO/EHLO 24.23%
56 5xx Reject unknown user 21.54%
1 5xx Reject recipient address 0.38%
-------- --------------------------------------------------
260 Total 5xx Rejects 100.00%
======== ==================================================
3 4xx Reject HELO/EHLO 100.00%
-------- --------------------------------------------------
3 Total 4xx Rejects 100.00%
======== ==================================================
359 Connections 359
280 Connections lost (inbound) 280
359 Disconnections 359
16375 Postscreen 16,375
2 Connection failures (outbound) 2
62 Timeouts (inbound) 62
8 Hostname verification errors (FCRDNS) 8
2 TLS connections (server) 2
1 TLS connections (client) 1
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.