Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Limit SASL Login failure attempts

Status
Not open for further replies.
Jul 6, 2010
2
GB
Hi All,

I cannot for the life of me (and I've done lots of reading) figure out how to stop someone hammering our Mail Servers with SASL login attempts.

I've limited TLS connections and SMTP connections which helps other types of floods but I'd like to stop someone running a dictionary-type attack and drop their connection after three password failures.

An Postfix gurus aware of a fix ?

Many thanks,

JR :)
 
I don't recall anything in Postfix itself that has this functionality. The closest that it may come is to choke off functions after too many errors, as defined by the hard limit and soft limit on errors.

I believe that Fail2Ban can do this, which is commonly used for this purpose on SSH servers. You may need to create a custom rule for postfix if one doesn't exist, which pretty much amounts to writing a regex expression.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top