Quantcast
Channel: Spiceworks Community
Viewing all articles
Browse latest Browse all 7477

This IP is infected (or NATting for a computer that is infected) with the keliho

$
0
0

Our IP was being blocked and we were (are?) on some spam list. I went to one machine that was showing lots of connections on my ASA 5510. I ran a netstat -a and could see maybe 1000 smtp connections. I took the PC off line and removed us from some blocked list. Now my question is do I have to explicitly tell the ASA to block smtp per IP address or IP address range? I only set the ASA to accept smtp from exchange, and our Barracuda spam/firewall. I set the ASA up with a network obj. 

Outside > Inside (exchange) smtp

inside (exchange) > Outside smtp


Am I missing something? The users was running some kind of Motorola program that gave him asses to his PC from his phone (at least that's what it looked like) and it had our public IP listed in the setting. Im not sure how it or he got our public but could that have thwarted our attempt to block traffic through the firewall?  



Viewing all articles
Browse latest Browse all 7477

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>