Community discussions

MikroTik App
 
User avatar
BartoszP
Forum Guru
Forum Guru
Topic Author
Posts: 3095
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Spam filtering - how to improve my antispam system

Sun Jan 06, 2019 10:40 pm

Hi,

I use Barracuda Spam Filter (Barracude ESG) as my spam-firewall for one of my customers.
It does good job but one of their e-mail's was used for communication with China based client. Since then we receive hundreds spam e-mails per day only for this used e-mail. We do not receive e-mails to admin@..., postamster@...., office@... or any other easy to guess addresses. Just for this one.
Trying different settings for ESG but there was no "wow" effect.
Today I decided to look for China's IP ranges and block it at router's level and block all SMTP traffic from these addresses.
We have no clients in Chine so I do not harm our business. I have impleneted it circa at 11 am. Look at THE EFFECT.

RED IS BAD :lol:
You do not have the required permissions to view the files attached to this post.
 
User avatar
sebastia
Forum Guru
Forum Guru
Posts: 1782
Joined: Tue Oct 12, 2010 3:23 am
Location: Antwerp, BE

Re: Spam filtering - how to improve my antispam system

Mon Jan 07, 2019 1:04 am

Nice out of the box thinking!
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22257
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Spam filtering - how to improve my antispam system

Mon Jan 07, 2019 5:30 am

I'm disappointed at the crappy level of service you provided to your clients until you implemented proper country blocking ;-p
Just kidding, nice touch!!
 
User avatar
BartoszP
Forum Guru
Forum Guru
Topic Author
Posts: 3095
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: Spam filtering - how to improve my antispam system

Mon Jan 07, 2019 10:35 am

Almost 24 hours later

Edit ... blocked at RAW firewall level
Chiny4.PNG
You do not have the required permissions to view the files attached to this post.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 22257
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: Spam filtering - how to improve my antispam system

Mon Jan 07, 2019 3:55 pm

Bartosz, country blocking is one of the many value added security prongs in the MOAB service that one of our forum folk provides for his clients and recently made available to all.
You should check it out.
viewtopic.php?t=137632
 
Xtremer
just joined
Posts: 4
Joined: Tue Feb 06, 2018 9:10 pm

Re: Spam filtering - how to improve my antispam system

Wed Jan 09, 2019 7:46 pm

Can you please add a post with your blocking rules and ip address list for this solution.

Thank you for your time.
 
User avatar
BartoszP
Forum Guru
Forum Guru
Topic Author
Posts: 3095
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: Spam filtering - how to improve my antispam system

Wed Jan 09, 2019 8:14 pm

@anav:

Barracuda ESG does good job .. it filters most of spam from China ... most means 99% ... but I was tired skipping whole pages of "dropped/blocked" entries and decided to not allow such e-mails to reach ESG

@Xtreamer:

Please check attachment. It is part of a bigger set of rules so you must to tailor it to your nedds as we have more than one WAN interface, more rules adding to RAWATTACK address list etc. These lines in the attachment are crucial ones
You do not have the required permissions to view the files attached to this post.
 
Xtremer
just joined
Posts: 4
Joined: Tue Feb 06, 2018 9:10 pm

Re: Spam filtering - how to improve my antispam system

Wed Jan 09, 2019 9:28 pm

Thank you BartoszP.
 
tippenring
Member
Member
Posts: 304
Joined: Thu Oct 02, 2014 8:54 pm
Location: St Louis MO
Contact:

Re: Spam filtering - how to improve my antispam system

Wed Jan 09, 2019 10:14 pm

Can you please add a post with your blocking rules and ip address list for this solution.

Thank you for your time.
Here's my process to create a US-based network address list for geofencing. You may wish to name your address list differently of course.

1. Copy the US-based address list here to N++.
2. Prepend "add list=US address=" to each subnet (in notepad++ do regex search for ^ replace with "add list=US address=", or use the TextFX plugin to insert a clipboard value to the beginning of each line)
3. Add "/ip firewall address-list" as the first line of the file.
4. Save the file and copy it to the router.
5. Open a terminal window and type "import <filename>".

Use the address list as desired in the firewall rules.
 
User avatar
BartoszP
Forum Guru
Forum Guru
Topic Author
Posts: 3095
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: Spam filtering - how to improve my antispam system

Thu Jan 10, 2019 10:34 am

I use N++ with it's regular expression search+replace/replace all option.
You do not have the required permissions to view the files attached to this post.