[PLUG] Something I don't want in my maillog...

Michael Robinson plug_0 at robinson-west.com
Sun Apr 11 15:38:02 UTC 2004


I could try to block every ip off from three subnets trying to sending
to a nonexistent account at my site, it's tedious though blocking
individual ip's and I'm well over a hundred of them now.  There
has to be a way to tell postfix I don't want it to log people who
can't get past the hello stage because they want to send to certain
nonexistent accounts.  If someone wanted to understand I'm not
listening, they would by now because they are not allowed to send
me data.  With the number of addresses in the same subnet trying
to send me this, it is clearly a virus or worm that I'm fighting.

On the other hand, there are rare cases where I want to see a record of
failure to send to a nonexistent account that should exist.  Maybe someone
came by the site and wants to contact someone through it thinking there's
an account for this person.  There's also the braindead providence network,
mail from inside the hospital never comes from a globally registered
address.  I had to turn off unknown hostname in helo checks because
I can't consistently get this to override for Providence.  I figured out
a long time ago that the name of the computer in the private network
behind the Internet connection hosting the mail should have the same
name that is used on the Internet side.  I have an external and
an internal goose record.  Providence should at least masquerade
to an address that can actually be looked up.

I'm tired of the log pollution because there's the inefficiency of logging
so much and log pollution makes it harder to see meaningful errors.





More information about the PLUG mailing list