I am currently running ASL to protect my home network and email server. Recently, my server was highjacked by an individual(s) whose IPs are from Russia. They were using my server to send well over 10,000 emails through my SMTP gateway.
We'll after being alterted over 10,000 times, I created 4 network objects for the four IP addresses that were sending the SPAM. I then created a network object called {Banned_Networks} and setup a filter of {Banned_Networks} -> Any Service -> Any Network -> DROP. I then made that the first rule of my list.
Oddly enough, SPAM was still getting through.
I then applied the same rule but substituted {Banned_Networks} with the individual IP. Had to do that 4 times. The SPAMMING got better, but to my suprise, I was still getting messages as of this morning informing me that at least 5-6 messages got through.
Am I doing something wrong here?
Thanks in advance.
This thread was automatically locked due to age.