02 Sep 2010 
Icewarp Support Center » Knowledgebase » Technical Help » Email Filtering/Routing » Intrusion Prevention
 Login [Lost Password] 
Email:
Password:
Remember Me:
 
 Search
 Article Options
 Intrusion Prevention
Solution

Intrusion prevention basics

Intrusion prevention, formerly called tarpitting, is a great feature, which has one main feature of avoiding spam dictionary attacks, where spammers try to send messages to any addresses they have on their dictionary containing thousands of words.

If remote server sends a message to x wrong recipients, it is blocked for the specific time.

Check the screen below for recommend Intrusion prevention settings, where we block cross session attempts to send mail to up to 5 unknown accounts, and block IP’s for 4 hours (240 min).

Intrusion prevention recommended settings

Press F1 on the Intrusion Prevention tab for information on each option.

Note the maximum message size of 100 MB. It is important, because usually SMTP cannot block a message due to it’s file size being over the limit you specified, until it receives it completely. With this option, if someone is sending a message and it reaches 100 MB, that person’s IP is also blocked for 4 hours.

Note that most options in Icewarp, including Intrusion Prevention, have a Bypass feature (B button), where you can specify IP’s or domains that you do not want to be detected as intruders ever. In Icewarp 9 you have an option in the Bypass button to Bypass all local senders, so that your own customers are not tarpitted. Note also that by using SMTP Auth (or other method that your support such as a Trusted IP or POP before SMTP), your customer should usually not be tarpitted.

More information can be find in FAQ:How to configure AntiSpam and mail server security



Article Details
Article ID: 494
Created On: 27 May 2008 07:32 PM

 This answer was helpful  This answer was not helpful

 Back
Home | Register | Submit a Ticket | Knowledgebase | Troubleshooter | News | Downloads
Language: