nanog mailing list archives

Re: Finding asymmetric path


From: Suresh Ramasubramanian <ops.lists () gmail com>
Date: Sun, 29 Nov 2009 08:32:31 +0530

Yes - term the account would be my recommendation

And if you filter port 25 traffic do it both ways

Read these old nanog threads ..
http://www.irbs.net/internet/nanog/0408/0465.html and
http://www.mail-archive.com/nanog () merit edu/msg28863.html

On Sun, Nov 29, 2009 at 3:58 AM, William Herrin
<herrin-nanog () dirtside com> wrote:
On Sat, Nov 28, 2009 at 2:14 PM, ML <ml () kenweb org> wrote:
Brielle is correct.  The customer in question is spamming networks and we
are having trouble filtering them because another provider allows them to
source traffic however they please.

What trouble? SMTP requires two-way traffic with a static port number
that nothing else uses. If for some reason you don't want to simply
terminate their account altogether, block packets outbound to your
customer sourced from TCP port 25 but not from your SMTP smarthosts.

Seriously though, if you can prove they're spamming (regardless of
whether the packets pass through your network) save yourself some
grief and just terminate the account.

Regards,
Bill Herrin


--
William D. Herrin ................ herrin () dirtside com  bill () herrin us
3005 Crane Dr. ...................... Web: <http://bill.herrin.us/>
Falls Church, VA 22042-3004





-- 
Suresh Ramasubramanian (ops.lists () gmail com)


Current thread: