Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] gstewart@example.com mail not working
- Date: Mon, 15 Mar 2010 08:02:54 +0100
- From: Attila Kinali <attila@example.com>
- Subject: Re: [tlug] gstewart@example.com mail not working
- References: <20100314102039.GH8643@example.com> <20100314143024.b65653c0.gstewart@example.com> <20100314214456.GD5314@example.com> <44657.81.109.50.38.1268607205.squirrel@example.com>
- Organization: NERV
Moin, On Sun, 14 Mar 2010 22:53:25 -0000 (GMT) "Godwin Stewart" <gstewart@example.com> wrote: > > Or are you just completely unaware that you could avoid rudely wasting > > people's time by allowing the connection and sending a standard "554 > > 5.7.1 Service unavailable; Client host [1.2.3.4] blocked because I > > refuse mail from all Asian hosts" or whatever? > > That's what I used to do until my server was getting hammered by dozens of > SMTP sessions per second, effectively becoming an ongoing DDoS attack. > Using the MTA to reject those connections was not something that was going > to scale and I was not about to start spending more money to get a better > server with more bandwith, more RAM and more horsepower. Here, i have to agree with Curt. I don't think that a machine can be brought down by SMTP alone. Not with so little connections. Of course, unless you are using a 386 for your mails. Being a free-time-sysadmin myself, and one that is managing some servers with high exposure, i've to say, that i've not seen any of my machines being brought down by any single service (save one instance where a cgi script that used a lot of CPU was hammered directly, but that's IMHO sysadmin fault). IMHO the right solution would be to rate limit all incomming connection. Linux provides nice ways that you can limit the number of new connections per second. Also, you should not drop the incomming packets completely but instead send an ICMP port not reachable (aka use -j REJECT), this way it'll be clear to the sysadmin, that the host itself is up, but something else is going on. Attila Kinali -- If you want to walk fast, walk alone. If you want to walk far, walk together. -- African proverb
- Follow-Ups:
- Re: [tlug] gstewart@example.com mail not working
- From: Christian Horn
- References:
- [tlug] gstewart@example.com mail not working
- From: Curt Sampson
- Re: [tlug] gstewart@example.com mail not working
- From: Godwin Stewart
- Re: [tlug] gstewart@example.com mail not working
- From: Curt Sampson
- Re: [tlug] gstewart@example.com mail not working
- From: Godwin Stewart
Home | Main Index | Thread Index
- Prev by Date: [tlug] Meeting Notes: TLUG Open Meeting: March 13, 2010
- Next by Date: Re: [tlug] power adapters in Japan (and US)
- Previous by thread: Re: [tlug] gstewart@example.com mail not working
- Next by thread: Re: [tlug] gstewart@example.com mail not working
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links