![]() |
|
|||||||
| Network / Server Status Please check often for network / Server updates here! |
![]() |
|
|
Thread Tools | Display Modes |
|
#211
|
||||
|
||||
|
Yea I am not to good with macs either.. Never used one for more than 10 min in my life. lol
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#212
|
||||
|
||||
|
Quote:
![]() Also i take it this is only on mail's 7 & 8 at the moment. any plans to shift to the othere mail servers? Last edited by Silverbug : 11-23-2006 at 02:29 PM. |
|
#213
|
|||||||||||
|
|||||||||||
|
Quote:
I just wanted to say thank you very much for setting up this new solution to fix the mail problem with mail7 and to stop the spam. It seems to work really well Happy Thanksgiving everyone! Rayan |
|
#214
|
||||
|
||||
|
Quote:
![]() We will keep adding it to the systems and does not affect mail when we turn it up. Think we should send another email? I think the last one was clear but maybe to let everyone know it will be going cluster wide with in the next 15 to 30 days. BTW someone asked what it is, it's called spamD here is the man page for it http://www.openbsd.org/cgi-bin/man.c...pamd&sektion=8 and more info: http://beta.freebsddiary.org/pf.php We will also be adding these to it: http://www.greylisting.org/whitelisting.shtml if not already added, I think Aaron might have already done it, not sure since today was a holiday.
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
Last edited by admin : 11-23-2006 at 09:40 PM. |
|
#215
|
||||
|
||||
|
AND HERE IS WHAT MAKES THE SYSTEM SO GOOD AND MAY ANSWER EVERYONES QUESTIONS:
Since SMTP is considered an unreliable transport, the possibility of temporary failures is built into the core spec (see RFC 821). As such, any well behaved message transfer agent (MTA) should attempt retries if given an appropriate temporary failure code for a delivery attempt (see below for discussion of issues concerning non-conforming MTA's). During the initial testing of Greylisting in mid-2003, it was observed that the vast majority of spam appears to be sent from applications designed specifically for spamming. These applications appear to adopt the "fire-and-forget" methodology. That is, they attempt to send the spam to one or several MX hosts for a domain, but then never attempt a true retry as a real MTA would. From our testing, this means that in the test environment, based on a fairly conservative interpretation of testing data, we have attained an effectiveness of over 95%, and that is with no legitimate mail ever being permanently blocked. In addition, with the recent rampant proliferation of email-based viruses, Greylisting has been shown to be extremely effective in blocking these viruses, as they also do not tend to retry deliveries. And since these viruses are fairly large, bandwidth and processing savings are significant versus the standard method of accepting delivery and local virus scanning. This blocking comes with a minimal price from the terms of local resources. Assuming the use of a local datastore for the triplet and other metadata, there is no required network traffic caused by Greylisting other than that associated with the connection itself. Since we are not checking the contents of the message at all there is very little processing overhead, unlike many other spam blocking methods. There is one effect that could be seen as either a positive or negative. Since the Greylisting method delays acceptance of unknown mail, that will generate a little more work for the sending MTA of legitimate mail. The flip side is that it generates a lot more work and smarts for the spammer's systems, hopefully enough to make the costs of spamming higher, possibly even to the point of making spamming unprofitable for some of them. The best part is that since we never permanently fail a message delivery, as long as the delivering MTA's are well behaved, we should never cause a legitimate mail to bounce. There should never be a false positive! FROM: http://projects.puremagic.com/greyli...hitepaper.html
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#216
|
||||||||||||
|
||||||||||||
|
Haven't had any problems with this now, this is just a friendly reminder...
Previous experience tells me that (client-side) firewalls often is a source of problems when switching ports. Especially corporate firewalls can some times be very strictly configured. So if you're having problems after switching port, a good place to start is to see if firewalls let traffic pass... Though this probably won't be that common a problem, as port 2525 have become a rather commonly used (alternative) port for SMTP... |
|
#217
|
||||
|
||||
|
I think I have seen like 2 tickets about firewalls other than personal so it has not been bad but it's only 3 mail servers.
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#218
|
|||||||||||
|
|||||||||||
|
with regards to the source of the problem, any way to prevent such things from happening again?
My clients has been displeased with regards to this issue. |
|
#219
|
||||||||||||
|
||||||||||||
|
Brad, I'm intrigued with this method. Thanks for the link--interesting reading. It appears that this method is so very simple but yet looks like it maybe one of the answers we all have been looking for. Good job!
On a different note--is there any other user-level controls that can be freely implemented so as to give the appearance of more control to our clients? The more settings that my customers can fiddle with when they are unhappy with the level of spam the happier they seem to be. Not sure if everyone else has had the same experience.
__________________
Up, up and whoa! Just getting out of my chair. |
|
#220
|
||||
|
||||
|
Quote:
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#221
|
||||
|
||||
|
Quote:
Yep that is why we are putting spamD on all the mail servers so we don't have to worry about port 25 attacks on the mail server as much. We are also keeping the proxy box setup so if it ever happens again we can just slap it right in front of the servers that is needed and will take about 10 min to stop a big SMTP attack.
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#222
|
|||||||||||
|
|||||||||||
|
It is possible that TODAY mail7 is still with problems?
A customer did't recive an email sent four times. Onty at the fifth attempt he got te message.
__________________
E Martire _____________________________ Linux & Windows Multidominio http://www.ole-web.net If you don't fight.....run! |
|
#223
|
||||
|
||||
|
No we have not seen any problems, did she get a bounce and was it an email sent from out side to mail7 or mail7 out. It might be best to open a ticket we could check the logs in spamd maybe if we know the IP of the sending mail server and the logs on the mail server. But I have not seen many mail tickets today or issues.
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
|
#224
|
|||||||||||
|
|||||||||||
|
Brad, this problem seems to be persisting some. I had a client email me yesterday to my account on mail7 and cc an account on mail3. The one for mail3 arrived a little over 22 hours ago, still no mail in the mail7 account. She received a delayed message right away but has not received anything since. The mail is coming from doodle1.hotdoodle.com.
Kent |
|
#225
|
||||
|
||||
|
Open a ticket and be sure to include the delayed message and headers.
__________________
Brad Pugh http://www.vortechhosting.com ------ Local System/Network Monitor http://nagios.hsphere.cc/ Login:guest Pass:guest XML FEED http://nagios.hsphere.cc/feed.xml ------ My Other Life:
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| 1.30.06 - Mail7 | aaron | Network / Server Status | 11 | 02-01-2006 01:31 AM |
| Mail7 2PM 10/07/2005 | dvanburen | Network / Server Status | 3 | 10-07-2005 03:40 PM |
| spamGuard Mail - Mail7 and unix - unix14 | admin | News and Announcements | 45 | 03-23-2005 01:50 PM |
| New Mail Server mail7.hsphere.cc | admin | News and Announcements | 6 | 12-31-2004 12:52 AM |