Hola estimados señores, aca realize unas busquedas de mis logs y se los copie pero sino pueden verlo con claridad el archivo se los adjuntos, para ver, que persona con más experiencia pueda indicar el comportamiento del servidor ZIMBRA :( algunos dices aplicar iptables ni idea como se come el IPTABLE pero si lo hago y bloqueo el puerto 25, ni enviare ni recibire correos.... Gracias por el aporte de cada uno y de mantener este grupo, muchas gracias y espero que puedan sacar sus conclusiones..
Informacion del servidor:
----------------------------------------------------------------------------------------
ESTE ES UN TAIL PARA EL USUARIO LDIAZ EL MISMO ESTA ELIMINADO Y SIGUE ENVIANDO CORREO
----------------------------------------------------------------------------------------
tail -f /var/log/zimbra.log |grep postfix |grep
lad...@MIDOMINIO.COMMay 18 09:30:36 mail postfix/smtp[15077]: 7062F74C067: to=<
christ...@sohu.com>, relay=
sohumx.h.a.sohu.com[61.135.132.110]:25, delay=94052, delays=93679/205/107/61, dsn=4.1.8, status=deferred (host
sohumx.h.a.sohu.com[61.135.132.110] said: 450 4.1.8 <
lad...@MIDOMINIO.COM>: Sender address rejected: Domain not found (in reply to RCPT TO command))
May 18 09:33:38 mail postfix/qmgr[31957]: 38AD274C071: from=<
lad...@MIDOMINIO.COM>, size=2971, nrcpt=50 (queue active)
May 18 09:33:45 mail postfix/qmgr[31957]: EAF2A745C18: from=<
lad...@MIDOMINIO.COM>, size=2972, nrcpt=50 (queue active)
May 18 09:33:45 mail postfix/qmgr[31957]: E7C6A74C0A8: from=<
lad...@MIDOMINIO.COM>, size=2972, nrcpt=50 (queue active)
----------------------------------------------------------------------------------------
REVISANDO EN LA BITACORA ME ENCONTRE CON ESTE DETALLE, EL USUARIO ESTA ELIMINADO Y ESA IP ES DESCONOCIDA
----------------------------------------------------------------------------------------
2010-05-17 05:31:27,169 INFO [btpool0-564] [name=
lad...@MIDOMINIO.COM;oip=41.184.65.177;ua=zclient/5.0.13_GA_2791.DEBIAN4.0;]
security - cmd=Auth; account=
lad...@MIDOMINIO.COM; protocol=soap;
2010-05-17 05:32:24,304 INFO [btpool0-628] [name=
lad...@MIDOMINIO.COM;oip=41.184.65.177;ua=zclient/5.0.13_GA_2791.DEBIAN4.0;]
security - cmd=Auth; account=
lad...@MIDOMINIO.COM; protocol=soap;
2010-05-17 05:34:30,219 INFO [btpool0-628] [name=
lad...@MIDOMINIO.COM;oip=41.184.65.177;ua=zclient/5.0.13_GA_2791.DEBIAN4.0;]
security - cmd=Auth; account=
lad...@MIDOMINIO.COM; protocol=soap;
----------------------------------------------------------------------------------------
ESTA CUENTA ESTA ELIMINADA Y VEAN LO QUE DICE EL /var/log/mail.log
----------------------------------------------------------------------------------------
grep ztotumo@MI\.DOMINIO\. /var/log/mail.log | grep -v 'deferred'
May 18 06:36:45 mail postfix/smtpd[3719]: NOQUEUE: reject: RCPT from
isls-mx20.wmin.ac.uk[161.74.14.113]: 550 5.1.1 <
zto...@MIDOMINIO.COM>: Recipient address rejected:
MIDOMINIO.COM; from=<> to=<
zto...@MIDOMINIO.COM> proto=ESMTP helo=<
isls-mx20.wmin.ac.uk>
May 18 06:43:58 mail postfix/smtpd[3720]: NOQUEUE: reject: RCPT from unknown[193.194.86.122]: 550 5.1.1 <
zto...@MIDOMINIO.COM>: Recipient address rejected:
MIDOMINIO.COM; from=<> to=<
zto...@MIDOMINIO.COM> proto=SMTP helo=<
mail2.univ-mosta.dz>
May 18 06:46:16 mail postfix/smtpd[991]: NOQUEUE: reject: RCPT from
mailob.kodeks.com[85.114.8.77]: 550 5.1.1 <
zto...@MIDOMINIO.COM>: Recipient address rejected:
MIDOMINIO.COM; from=<> to=<
zto...@MIDOMINIO.COM> proto=SMTP helo=<
mail.kodeks.com>
May 18 06:51:11 mail postfix/smtpd[4292]: NOQUEUE: reject: RCPT from
isls-mx20.wmin.ac.uk[161.74.14.113]: 550 5.1.1 <
zto...@MIDOMINIO.COM>: Recipient address rejected:
MIDOMINIO.COM; from=<> to=<
zto...@MIDOMINIO.COM> proto=ESMTP helo=<
isls-mx20.wmin.ac.uk>
May 18 06:56:18 mail postfix/smtpd[11335]: NOQUEUE: reject: RCPT from
mailob.kodeks.com[85.114.8.77]: 550 5.1.1 <
zto...@MIDOMINIO.COM>: Recipient address rejected:
MIDOMINIO.COM; from=<> to=<
zto...@MIDOMINIO.COM> proto=SMTP helo=<
mail.kodeks.com>
May 18 06:59:57 mail postfix/smtpd[13637]: NOQUEUE: reject: RCPT from unknown[207.97.221.115]: 550 5.1.1 <
zto...@MIDOMINIO.COM>: Recipient address rejected:
MIDOMINIO.COM; from=<> to=<
zto...@MIDOMINIO.COM> proto=ESMTP helo=<
ns.aemserver.com>
May 18 07:12:36 mail postfix/smtpd[11334]: NOQUEUE: reject: RCPT from
server88-208-222-189.live-servers.net[88.208.222.189]: 550 5.1.1 <
zto...@MIDOMINIO.COM>: Recipient address rejected:
MIDOMINIO.COM; from=<> to=<
zto...@MIDOMINIO.COM> proto=SMTP helo=<
localhost.wales.com>
May 18 07:30:19 mail postfix/smtpd[11929]: NOQUEUE: reject: RCPT from unknown[212.182.115.23]: 550 5.1.1 <
zto...@MIDOMINIO.COM>: Recipient address rejected:
MIDOMINIO.COM; from=<> to=<
zto...@MIDOMINIO.COM> proto=ESMTP helo=<
smaug.forumakad.pl>
May 18 07:56:19 mail postfix/smtpd[14524]: NOQUEUE: reject: RCPT from
mailob.kodeks.com[85.114.8.77]: 550 5.1.1
---///---///---///---///---///---///---/---///---///---///---///---///---///---///---///---///---///---///---/////---///