Networking Forums

Networking Forums > Computer Networking > Linux Networking > Need some expert advice with iptables port 25 (rate limiting) orusing tcp_wrappers

Reply
Thread Tools Display Modes

Need some expert advice with iptables port 25 (rate limiting) orusing tcp_wrappers

 
 
Linux_User01
Guest
Posts: n/a

 
      01-16-2011, 11:27 PM
I have 2 email servers both running RHEL5 Linux, the main ISP server
has less than 5,500 accounts on it.
The other virtual domain server has about 500 accounts both run
IceWarp.

I have problems with rouge overseas traffic hitting the email servers,
I have written some iptables rules to block overseas traffic to port
443.

However the problem is I do not know how to rate limit port 25 due to
the fact Smart_Phones such as iPhone/Android/BlackBerry connect via
port 25 as well. There are 2 Barracuda 800(s) that sit in front as
MX(s), what has happened in the past is I have found some malicious
overseas
IP ranges or they can be stateside spamming, so I block them in the
Barracuda(s). When this is done they normally turn around and launch
a
denial of service attack against the email server on port 25 or port
110 by bombarding it with thousands of request or bogus user_name/
password
combo's to disrupt service.

Does anyone have any ideas about using iptables and rate limiting
connections to port 25 without impacting Smart_Phones that connect or
the Barracuda(s).

I was thinking I could have separate rules for the Barracuda(s) to
port 25, however this would mean that Smat_phones would fall into this
realm.

Someone mentioned tcp_wrappers, I want to keep the port(s) 110/25
facing the outside world from being bombarded by a Malicious denial
of
service attack.

Any help or ideas would be great.

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Rate limiting (old way and new) D. Stussy Linux Networking 3 03-06-2008 01:39 AM
Iptables to Manage web-Attacks [Linux Expert] Pseudonyme Linux Networking 7 02-18-2008 07:57 AM
I need an expert advice on this =?Utf-8?B?Q2hyaXM=?= Windows Networking 3 12-17-2004 05:57 AM
Expert advice needed, Please Rick Windows Networking 2 01-23-2004 06:32 PM
** Help REQ: Rate Limiting on Virtual Interfaces NoNameHere Linux Networking 1 12-10-2003 08:15 PM



1 2 3 4 5 6 7 8 9 10 11