You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
On a Mailcow server I now have these Netfilter settings (you can see from the logs below that these variables were set to ban for longer):
Ban time (s): 600
Max. attempts: 10
Max. attempts: 300
IPv4 subnet size to apply ban on (8-32): 8
IPv6 subnet size to apply ban on (8-128): 8
Today there have been brute force attempts / a user with a misconfigured client from a Virgin Media IP address (they are the only cable Internet provider in the UK and perhaps have around a third or even a half of the market):
docker-compose logs --no-color netfilter-mailcow | grep " 86\."
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 9 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 8 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 7 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 6 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 5 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 4 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 3 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 2 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 1 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 30 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 30 minutes
netfilter-mailcow_1_873dbec7bd16 | Unbanning 86.0.0.0/8
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 9 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 8 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 7 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 6 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 5 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 4 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 3 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 2 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 1 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 30 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 30 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 30 minutes
netfilter-mailcow_1_873dbec7bd16 | Unbanning 86.0.0.0/8
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 9 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 8 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 7 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 6 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 5 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 4 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 3 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 2 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 1 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 30 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 30 minutes
netfilter-mailcow_1_873dbec7bd16 | Unbanning 86.0.0.0/8
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 9 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 8 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 7 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 6 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 5 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 4 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 3 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 2 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 1 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 30 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 30 minutes
netfilter-mailcow_1_873dbec7bd16 | Unbanning 86.0.0.0/8
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 9 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 8 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 7 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 6 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 5 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 4 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 3 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 2 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 1 more attempts in the next 600 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 30 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 30 minutes
netfilter-mailcow_1_873dbec7bd16 | Unbanning 86.0.0.0/8
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 9 more attempts in the next 120 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 8 more attempts in the next 120 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 7 more attempts in the next 120 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | Unbanning 86.0.0.0/8
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 9 more attempts in the next 120 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 8 more attempts in the next 120 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 7 more attempts in the next 120 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 6 more attempts in the next 120 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 5 more attempts in the next 120 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 9 more attempts in the next 120 seconds until 86.147.72.XX/32 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 8 more attempts in the next 120 seconds until 86.147.72.XX/32 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 7 more attempts in the next 120 seconds until 86.147.72.XX/32 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 6 more attempts in the next 120 seconds until 86.147.72.XX/32 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 5 more attempts in the next 120 seconds until 86.147.72.XX/32 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 4 more attempts in the next 120 seconds until 86.147.72.XX/32 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 3 more attempts in the next 120 seconds until 86.147.72.XX/32 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 2 more attempts in the next 120 seconds until 86.147.72.XX/32 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 1 more attempts in the next 120 seconds until 86.147.72.XX/32 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.147.72.XX/32 for 10 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.147.72.XX/32 for 10 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.147.72.XX/32 for 10 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.147.72.XX/32 for 10 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.147.72.XX/32 for 10 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.147.72.XX/32 for 10 minutes
netfilter-mailcow_1_873dbec7bd16 | Unbanning 86.147.72.XX/32
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 9 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 8 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 7 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 6 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 5 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 4 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 3 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 2 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 1 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 10 minutes
netfilter-mailcow_1_873dbec7bd16 | Unbanning 86.0.0.0/8
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 9 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 8 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 7 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 6 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 5 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 4 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 3 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 2 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 1 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | Unbanning 86.0.0.0/8
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 9 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 8 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 7 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 6 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 5 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 4 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 3 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 2 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | 1 more attempts in the next 300 seconds until 86.0.0.0/8 is banned
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 10 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 10 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 10 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 10 minutes
netfilter-mailcow_1_873dbec7bd16 | 86.147.72.XX matched rule id 2
netfilter-mailcow_1_873dbec7bd16 | Banning 86.0.0.0/8 for 10 minutes
Why is the whole of 80.0.0.0/8 being banned?
This policy has the danger of catching innocent IP addresses, would it be possible to just ban the offending IP address and not such a large subnet?
The text was updated successfully, but these errors were encountered:
19:59 <@golden_receiver> <chrisc> how come such a large network is banned,
19:59 <@golden_receiver> <chrisc> in the netfilter config i have IPv4 subnet size to apply ban on (8-32): 8
19:59 <@golden_receiver> that's why
19:59 <@golden_receiver> you ban /8
19:59 <@golden_receiver> 1.2.3.4 => 1.0.0.0/8
19:59 <@golden_receiver> and 1.0.0.0/8 is 1.0-255.0-255.0-255
19:59 <@golden_receiver> you should set it to 24 for IPv4
20:00 <@golden_receiver> and maybe 64 or 96 for IPv6
On a Mailcow server I now have these Netfilter settings (you can see from the logs below that these variables were set to ban for longer):
Today there have been brute force attempts / a user with a misconfigured client from a Virgin Media IP address (they are the only cable Internet provider in the UK and perhaps have around a third or even a half of the market):
Why is the whole of
80.0.0.0/8
being banned?This policy has the danger of catching innocent IP addresses, would it be possible to just ban the offending IP address and not such a large subnet?
The text was updated successfully, but these errors were encountered: