GFI Software

Welcome to the GFI Software community forum! For support please open a ticket from https://support.gfi.com.

Home » GFI User Forums » Kerio Connect » Anti Hammering SASL IP address blocking not working (LOG Files entries with password guessing)
Anti Hammering SASL IP address blocking not working [message #149457] Fri, 05 March 2021 08:02 Go to next message
krischeu is currently offline  krischeu
Messages: 5
Registered: March 2019
Hi,
I am using kerio connect and I have much password guessing entries in my log.
Anti hammering in mailconfig is done like the description here:

But my entries are still like this:
[05/Mar/2021 07:49:27] Failed SMTP login from 212.70.149.71 with SASL method LOGIN.
[05/Mar/2021 07:50:35] SMTP: User fantasy<_at_>carhs.de doesn't exist. Attempt from IP address 212.70.149.71.
[05/Mar/2021 07:50:41] Failed SMTP login from 212.70.149.71 with SASL method LOGIN.
[05/Mar/2021 07:51:14] SMTP: User fantasy<_at_>carhs.de doesn't exist. Attempt from IP address 212.70.149.71.
[05/Mar/2021 07:51:20] Failed SMTP login from 212.70.149.71 with SASL method LOGIN.
[05/Mar/2021 07:52:28] SMTP: User fanyi<_at_>carhs.de doesn't exist. Attempt from IP address 212.70.149.71.
[05/Mar/2021 07:52:34] Failed SMTP login from 212.70.149.71 with SASL method LOGIN.
[05/Mar/2021 07:53:06] SMTP: User fanyi<_at_>carhs.de doesn't exist. Attempt from IP address 212.70.149.71.
[05/Mar/2021 07:53:12] Failed SMTP login from 212.70.149.71 with SASL method LOGIN.
[05/Mar/2021 07:54:16] SMTP: User fao<_at_>carhs.de doesn't exist. Attempt from IP address 212.70.149.71.
[05/Mar/2021 07:54:22] Failed SMTP login from 212.70.149.71 with SASL method LOGIN.
[05/Mar/2021 07:54:57] SMTP: User fao<_at_>carhs.de doesn't exist. Attempt from IP address 212.70.149.71.
[05/Mar/2021 07:55:03] Failed SMTP login from 212.70.149.71 with SASL method LOGIN.
[05/Mar/2021 07:56:08] SMTP: User fap<_at_>carhs.de doesn't exist. Attempt from IP address 212.70.149.71.
[05/Mar/2021 07:56:14] Failed SMTP login from 212.70.149.71 with SASL method LOGIN.
[05/Mar/2021 07:56:48] SMTP: User fap<_at_>carhs.de doesn't exist. Attempt from IP address 212.70.149.71.
Re: Anti Hammering SASL IP address blocking not working [message #149468 is a reply to message #149457] Tue, 09 March 2021 08:55 Go to previous messageGo to next message
krischeu is currently offline  krischeu
Messages: 5
Registered: March 2019
nice forum
Re: Anti Hammering SASL IP address blocking not working [message #149473 is a reply to message #149457] Wed, 10 March 2021 01:29 Go to previous message
Nick.Geary is currently offline  Nick.Geary
Messages: 73
Registered: January 2021
The default setting to trigger anti-hammering is 10 failed logins within one minute. These attempts are spread out beyond the default 60 seconds configured. If you suspect it's a malicious attempt, you could either block the IP address or tighten the restrictions by lowering the Checktime and/or LockoutCount.

https://support.kerioconnect.gfi.com/hc/en-us/articles/36001 5185540-Configuring-AntiHammering-in-Kerio-Connect


Nick Geary
GFI Software
Previous Topic: Kerio Connect Relaying
Next Topic: MacOS and Kerio LDAP
Goto Forum:
  


Current Time: Sun Nov 27 09:51:32 CET 2022

Total time taken to generate the page: 0.02286 seconds