-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 On 19-06-15 21:25, Carmel NY wrote: > I just started using 'fail2ban" and have not figured out how to > create a custom filter. > > I am running Postfix-3.0.1 on a FreeBSD 10.1 system. My mail-log is > filling up with entries like this: > > Jun 19 06:29:40 scorpio postfix/smtpd[45535]: warning: hostname > abts-mum-static-025.109.170.122.airtelbroadband.in does not resolve > to address 122.170.109.25: hostname nor servname provided, or not > known > > That is all on one line, although it is shown wrapped here. > > "fail2ban" is not catching this. I need to create a rule that would > catch "hostname nor servname provided, or not known" or ""address > <IP>: hostname nor servname provided, or not known" for it but I am > not sure exactly how. I would appreciate it if someone could assist > me. >
These are warnings from postfix, they happen because the mail server has unexpected dns records, or because your dns setup is screwed up. While these warnings pop up more with spamming machines than with valid mail servers, they are not uncommon for valid senders. So don't block access based on these warnings. If you really want to block mail delivery for all senders that have DNS setup issues, you should look into the postfix config parameter "reject_unknown_reverse_client_hostname" or even "reject_unknown_client_hostname": they make postfix reject those connections directly. Tom -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJVhJEQAAoJEJPfMZ19VO/1THgP/1uAnWMEdXFhCbfzE4/6B6Ro vyduWX9Xg7dpQYZ+zHnrwaljgcwaiso9COJ4oaZ2M+a4+3/HmG5ucJ0pVTrKRfp6 m9CDDVeZbL4MPyTRhnrI33Ai0HZxmO8c5gwGAkfISGiiLzp4LMYsO3hHkXfnTMij W+NLt+gx3UgnJcPgALGEPbWnqLiREjstXWn5gfBwnoo9H3ye4JAjZygWydJXSm1o IbmPSDckLApWzMoM10wNARBQ6WnHwXUUMvcb8vSneNCYNNk1BNMWX0fs2h9f5VxY PBh8SxAlkIY5mwByeZNjbkydA47QujR/HL3tGU+YqgP/9EjthssPHO8+pa8P3kSQ 8XUtQQmJpAsOUmagrzFA4RkgVmqz9dc/4D//X52tn+Qkv6PXnWEUrdg2JrnnDmFy s9gW8knCWPkgjHo/AURjQweKEmHxhMBfHJkcVbx1nTI6nX6SKxvEiD/HYsPkzHU+ 7UIwZMrQ9ReMoEUUBbEHQRDrVynBr5+OJE1vEkvQYsv6J1vudzHo0cyyXLJ1yAZh U8RfqYGyvlbw6HNSZOL85Bi49pgCRPBNDZPsSWHg6JH+LT6NsDECMo1kq5w1+/Yi oBTkhclSlMirplyMBqMfro2SHhG+yoVdNEQEujWxT2uK0OBX/G4olfsDMu12pWTK YXdT/1aWVZI7uTdbNpuw =DpeE -----END PGP SIGNATURE----- ------------------------------------------------------------------------------ _______________________________________________ Fail2ban-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/fail2ban-users
