@gertjan said in Getting Hammered:
I you liked the port-knocking on "22", have a look at what happens on your port "25" and "443", you'll be amazed.
Seeing a few on 443 and a couple on 25.
Normally, your mail server already has something like fail2ban and a rather huge setup to filter out fake connection, like temptation to relay, temptations to load your inbox with spams, etc.
A (internal, on a LAN) web server (port 443) : same thing : a real hail storm.
Not filtering these servers can put a real load on your servers.
It is a Exchange server and not set up for routing mails and any attempt to route through it just gets rejected. I also have a large set of rules to reject spam but wanted to use pfBlockerNG to block out spamming IP's. YEs exchange can do it but requires the Edge Server to do it. Dont want another VM running to to do IP filtering.
I realise they are scripts trying as well on the ports rather than real humans.