DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Firewall breach?
- legal
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 65
- Thank yous received: 0
16 Jan 2015 12:18 #82403
by legal
Firewall breach? was created by legal
Hi - we are finding that we are getting access attempts on a server that is behind a 28xx - Strict firewall rules are set, NAT used but port redirection for 25 & 1723. In both cases there are then rules set to block all traffic on those ports then to allow traffic from specific destinations. despite this someone is running random scans on the system attempting to match user/password names! Any thoughts or suggestions as to what to check? Thanks.
Please Log in or Create an account to join the conversation.
- marjohn56
- Offline
- Junior Member
Less
More
- Posts: 84
- Thank yous received: 0
17 Jan 2015 11:48 #82415
by marjohn56
Replied by marjohn56 on topic Re: Firewall breach?
Port 25 SMTP...
Is your SMTP server open to all callers? If so then you will get these annyances. If you are running something like I do, where my primary MX record points to something like SpamHero, the mail is scanned and then sent back to me. I changed the SMTP port to something else, then set SpamHero's config to deliver to me on that port, that stopped all of the scans and attempts on my mail server. I did start out by having port 25 set to allow just SpamHereo addresses, but that caused a few issues as they can change.
Is your SMTP server open to all callers? If so then you will get these annyances. If you are running something like I do, where my primary MX record points to something like SpamHero, the mail is scanned and then sent back to me. I changed the SMTP port to something else, then set SpamHero's config to deliver to me on that port, that stopped all of the scans and attempts on my mail server. I did start out by having port 25 set to allow just SpamHereo addresses, but that caused a few issues as they can change.
Please Log in or Create an account to join the conversation.
- legal
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 65
- Thank yous received: 0
17 Jan 2015 17:25 #82416
by legal
Replied by legal on topic Re: Firewall breach?
Yes, I was trying to set a filter rule so that port 25 was only open to the filter service IP address - sounds as if you had tried that previously also? - can you run through how you set the rules even just in general terms? Thanks
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek