I have an issue with a 3.214 box. When I enable Squid proxy I start seeing frequent proxy requests from a few outside servers that then connect to SMTP ports of many servers.
Proxy is set to only allow the internal network. Transparent or Standard both seem to allow these outside servers to bounce email off Squid. Most of the connections are coming from one server today: 216.137.3.3 as well as a couple of others (64.xxx).
I then put in a rule to block port 8080 to the external interface and I start seeing frequent violations.
After a while the violations stop. If I enable proxy again the violations will eventually begin again (but not for some hours).
BTW, SMTP proxy is not turned on and I don't see anything unusual to/from the real SMTP server (besides the usual cracker crap). And, I have to use Proxy ARP to use the 5 routable IPs I have from the ISP. And FYI, the one routable IP that is the real SMTP server also runs the latest Apache and I don't see anything unusual there except those pesky worms and Formail attempts.
This thread was automatically locked due to age.