ZhangHuangbin wrote:Is the IP banned by Fail2ban while the issue happening?
No, not immediately. IP will banned after 5 attempts send email out.
Maillog:
Feb 9 14:20:42 mail postfix/submission/smtpd[29834]: connect from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:20:42 mail postfix/submission/smtpd[29835]: connect from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:20:42 mail postfix/submission/smtpd[29835]: lost connection after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:20:42 mail postfix/submission/smtpd[29835]: disconnect from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:20:42 mail postfix/submission/smtpd[29835]: connect from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:23:54 mail postfix/anvil[8953]: statistics: max connection rate 8/60s for (submission:46.131.33.220) at Feb 9 14:20:42
Feb 9 14:23:54 mail postfix/anvil[8953]: statistics: max connection count 5 for (submission:46.131.33.220) at Feb 9 14:20:42
Feb 9 14:25:08 mail postfix/submission/smtpd[29854]: connect from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:08 mail postfix/submission/smtpd[29854]: lost connection after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:08 mail postfix/submission/smtpd[29854]: disconnect from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:42 mail postfix/submission/smtpd[25277]: timeout after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:42 mail postfix/submission/smtpd[25277]: disconnect from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:42 mail postfix/submission/smtpd[29832]: timeout after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:42 mail postfix/submission/smtpd[29832]: disconnect from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:42 mail postfix/submission/smtpd[29833]: timeout after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:42 mail postfix/submission/smtpd[29833]: disconnect from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:42 mail postfix/submission/smtpd[29834]: timeout after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:42 mail postfix/submission/smtpd[29834]: disconnect from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:42 mail postfix/submission/smtpd[29835]: timeout after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
Feb 9 14:25:42 mail postfix/submission/smtpd[29835]: disconnect from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
And Fail2ban log:
2021-0 2-09T14:19:29.763766mail.saare.ee postfix/submission/smtpd[24840]: lost connection after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
2021-0 2-09T14:20:42.414592mail.saare.ee postfix/submission/smtpd[29834]: lost connection after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
2021-0 2-09T14:20:42.507655mail.saare.ee postfix/submission/smtpd[29834]: lost connection after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
2021-0 2-09T14:20:42.699971mail.saare.ee postfix/submission/smtpd[29835]: lost connection after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]
2021-0 2-09T14:25:08.920946mail.saare.ee postfix/submission/smtpd[29854]: lost connection after UNKNOWN from 220-33-131-46.dyn.estpak.ee[46.131.33.220]