Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SMTP outside of fw-rules?

Hi

I have a lot of spam and syn-floodig from 1 network. So i have created a rule that drop all communication from this network.

But i can see a lot of syn from this network in the connection-table to all smtp tcp-port (25/465/587)

Why this syn are not droped?

Regards

Peter



This thread was automatically locked due to age.
Parents
  • Hi Peter,

    maybe your rule to drop that traffic don’t work properly. Did you validate that? Maybe show how you designed that.

    Btw I think depending on the size of the attack you need support of a provider at backbone level or CDN.

    Best regards 

    Alex 

    -

Reply
  • Hi Peter,

    maybe your rule to drop that traffic don’t work properly. Did you validate that? Maybe show how you designed that.

    Btw I think depending on the size of the attack you need support of a provider at backbone level or CDN.

    Best regards 

    Alex 

    -

Children