connect from unknown

Discussion in 'Server Operation' started by Maede, Oct 17, 2019.

  1. Maede

    Maede New Member

    Hi everybody

    I use ISPConfig as my panel but have a lot of line as follow in my syslog file:
    postfix/smtpd warning: hostname swim.diverseenvironment.com does not resolve to address 185.211.245.198
    postfix/smtpd: connect from unknown[185.211.245.198]
    postfix/smtpd: lost connection after EHLO from unknown[185.211.245.198]
    postfix/smtpd: disconnect from unknown[185.211.245.198] ehlo=1 commands=1

    also when I check IPs , all of them known as "Attack Source". also I block some of them with UFW or iptable but the problem still remain. :(

    my emails work correct and send/receive done without problem.

    I'll really appreciate any help

    Thanks in advance
     
  2. till

    till Super Moderator Staff Member ISPConfig Developer

    There is no action needed, just ignore them.
     
  3. Maede

    Maede New Member

    Thanks a lot.
    I appreciate your help.
     
  4. Maede

    Maede New Member

    isn't there any way to decrease them?
     
  5. till

    till Super Moderator Staff Member ISPConfig Developer

    No, it's normal that such systems connect to any mail system that has a public internet IP.
     
  6. Steini86

    Steini86 Active Member

    You can not do anything agains occasional connection attempts. If it is the same IP trying to connect many times, you can block them automatically by the use of fail2ban.
    Anyway, they cause no harm as long as they are being blocked by postfix. You can decrease the loglevel, so you don't see them in your logs, but that will do nothing to the problem.
     
  7. Maede

    Maede New Member

    When I try to ban IPs that trying to connect many times, my postfix fall into problem (I can't send or receive any mail)
     
  8. Taleman

    Taleman Well-Known Member HowtoForge Supporter

    Is that a statement of fact or did you want some question answered?
     
  9. Maede

    Maede New Member

    Yes, actually this is a fact that occurred to me.
     
  10. Steini86

    Steini86 Active Member

    You should only block the ones that fail to connect, not the legitimate ones ;-)
    Anyway, as I said it makes almost no difference if the firewall drops the connection or postfix. (the firewall needs less ressources, but on a small server that should not become visible)
     

Share This Page