hi guys
I am receiving alerts of this type
more than 2 thousand connections to port 465
====================
Subject:
lfd on s1.MyServer.com: 200.x.y.76 blocked with too many connections
====================
Body:
Time: Thu Jul 27 15:32:37 2023 -0500
IP: 200.x.y.76
Connections: 2607
Blocked: Temporary Block for 1800 seconds [CT_LIMIT]
Connections:
tcp: 200.x.y.76:26717 -> 67.x.y.58:465 (SYN_RECV)
tcp: 200.x.y.76:61086 -> 67.x.y.58:465 (SYN_RECV)
tcp: 200.x.y.76:62815 -> 67.x.y.58:465 (SYN_RECV)
tcp: 200.x.y.76:65139 -> 67.x.y.58:465 (SYN_RECV)
tcp: 200.x.y.76:63776 -> 67.x.y.58:465 (SYN_RECV)
How can you solve this excessive or abuse of connection attempts?
I am receiving alerts of this type
more than 2 thousand connections to port 465
====================
Subject:
lfd on s1.MyServer.com: 200.x.y.76 blocked with too many connections
====================
Body:
Time: Thu Jul 27 15:32:37 2023 -0500
IP: 200.x.y.76
Connections: 2607
Blocked: Temporary Block for 1800 seconds [CT_LIMIT]
Connections:
tcp: 200.x.y.76:26717 -> 67.x.y.58:465 (SYN_RECV)
tcp: 200.x.y.76:61086 -> 67.x.y.58:465 (SYN_RECV)
tcp: 200.x.y.76:62815 -> 67.x.y.58:465 (SYN_RECV)
tcp: 200.x.y.76:65139 -> 67.x.y.58:465 (SYN_RECV)
tcp: 200.x.y.76:63776 -> 67.x.y.58:465 (SYN_RECV)
How can you solve this excessive or abuse of connection attempts?
Last edited by a moderator: