Prevent SPAM from Leaving the network. (ISP)

Hi,
I am working for an ISP, and we are having a few issues, im not sure how to fix.
My Scenario:
We are an ISP with 4 uplink providers and BGP sessions to 3 of them. We get full tables from 2 of them and partial tables from 1 of them.
Our business is the rental of servers, and we have about 500 servers at the present moment.
Every single server is on its own vlan with something like a /27.
When i get a customer asking for more than a /27, or when they ask the many different c-class subnets, i KNOW they way to use the server as a mail server.
I have created an ACL that looks like the following:
++++++++++++++++++++++++++++++++++++++++++++++++++++++
EDGE01.PRIVATELAYER.CH#show access-lists SPAM
Extended IP access list SPAM
    9 permit icmp any any (787857 matches)
    10 deny tcp any any eq pop3 (8106 matches)
    11 deny tcp any any eq pop2 (38 matches)
    12 deny tcp any any eq 27 (65 matches)
    13 deny udp any any eq 27 (2369 matches)
    14 deny tcp any any eq 58 (243 matches)
    15 deny udp any any eq 58 (2365 matches)
    16 deny tcp any any eq 61 (13 matches)
    17 deny udp any any eq 61 (2352 matches)
    18 deny tcp any any eq 24 (7 matches)
    19 deny udp any any eq 24 (2306 matches)
    20 deny tcp any any eq 143 (1266 matches)
    21 deny tcp any any eq 174 (3 matches)
    22 deny udp any any eq 174 (2347 matches)
    23 deny tcp any any eq 209 (468 matches)
    24 deny udp any any eq 209 (2326 matches)
    25 deny tcp any any eq 220 (3 matches)
    26 deny udp any any eq 220 (2328 matches)
    27 deny tcp any any eq 3206 (42285 matches)
    28 deny udp any any eq 3206 (2463 matches)
    29 deny tcp any any eq 3332 (42816 matches)
    30 deny tcp any any eq smtp (238570513 matches)
    31 deny udp any any eq 3332 (2354 matches)
    32 deny tcp any any eq 1723 (43657 matches)
    33 deny udp any any eq 1723 (2345 matches)
    40 deny tcp any any eq 585 (18 matches)
    50 deny tcp any any eq 993 (820 matches)
    60 deny tcp any any eq 995 (1233 matches)
    70 deny tcp any any eq 8080 (2025630 matches)
    100 permit ip any any (7969222 matches)
EDGE01.PRIVATELAYER.CH#
++++++++++++++++++++++++++++++++++++++++++++++++++++++
To my knowledge, this ACL should be catching ALL email ports, and dropping those packets.
I then get an email from Spamhaus, telling me that this server is sending email (SPAM)
When i asked them, they said that the customer might be using GRE tunnels to the server or asymmetric routing.
Im not familiar with asymmetric routing, but after doing some research, i think that GRE tunnels are normally configured ion port 1723, which is blocked as well.
Can anyone point me to the best way to prevent email from leaving an Interface Vlan (SVI)
I am working on a 65095 Series Switch.
If i should add something to the EDGE ACL, or something else, please advise.
Best Regards,
Ezequiel Pineda

Hi,
We have had this issue with very few people.
It looks like they are part of the Rosko Spam operation, which is a big deal, and being spammers with a LOT of spamming experience, they somehow have found a way to avoid ACL's.
At the moment yes, this is the only server that was causing the issue, but i have killed the account already, and shut the vlan.
I did however, create another ACL with the following statement, to try seeing exactly what was going on but couldnt see much to be honest
# 1 permit tcp any any log-input
# 2 permit udp any any log-input
I tried this with the log and log-input options, but i dont see Session information, Only TCP-IP source and destination traffic.
Can you elaborate more on that span session you mentioned?
Thanks again,
Ezequiel Pineda

Similar Messages

  • Why am I receiving a notice to update my version and then not able to click on it? It also prevents me from entering the internet if I put my computer to sleep with this update box there!

    The box appears after I'm on the internet. It's on my desktop when I go to shut down my computer and after I've shut down the internet. When I click on the x it doesn't disappear. When I click on the box indicating Yes, I'd like to update my version of Firefox it does nothing. If I leave this box there and put my computer to sleep it stays on and actually prevents me from entering the internet! I need to restart my computer or shut down! My computer is a MacBook Pro and is only one year old .

    They have to know who the person is who has their account set up wrong?   Do you know who they are or how to identify them?
    if not, how do you expect Verizon to find which user that is?
    Best thing for you to do is set up a mail filter and just throw those into the trash or delete them the second they come into your email box. 
    here are a couple walk throughs. 
    How to Filter Mail from a Certain Sender Easily in Win Live Mail, Outlook Expr.

  • How do I prevent Mail from Zipping the attachment?

    When I send a .pages file by e-mail, Mail zips the file to .pages.zip.
    The network software at this University blocks .zip. How do I prevent Mail from zipping the file? I tried turning off the "send windows-friendly", but but still zips.

    Assuming this is iWork '08 or earlier, the "documents" are actually packages. A package is really a folder hierarchy. A folder cannot be emailed unless it is archived somehow. Mail does this automatically; most other email programs would be incapable of sending a bare Pages document at all.
    You could use some other non-blocked archive format, like tar or StuffIt. Or maybe you could rename it so that the mail servers don't recognize it as zip. You would have to instruct your recipient to rename it back. I understand that iWork '09 archives documents by default, although they are not named .zip, so that should be no longer an issue.

  • Exchange 2013 prevent spam from my own domain

    Dear All,
    Back in Exchange 2007 we used to prevent spam from own domain by modifying permissions on the Receive Connector, as show on this link.
    http://exchangepedia.com/2008/09/how-to-prevent-annoying-spam-from-your-own-domain.html
    When I modify the same permissions on Exchange 2013 Default Front Receive Connector, the spam is still allowed threw.
    Is there a different aproche to achieve the same result in Exchange 2013?
    Thank you
    Bujar

    Hi Bujar,
    Have you tried to modify the permissions on Exchange 2013 default Hub transport Receive connector?
    As we know, for Exchange 2013, there have been major architectural changes to the Exchange server roles. Instead of the five server roles that were present in Exchange 2010 and Exchange 2007, in Exchange 2013, the number of server roles has been reduced
    to three: the Client Access server and the Mailbox server, and with Service Pack 1, the Edge Transport server role.
    The Exchange 2013 Mailbox server includes all many of the server components found in Exchange 2010: client access protocols, transport services, mailbox databases, and Unified Messaging services (the Client Access server redirects SIP traffic generated from
    incoming calls to the Mailbox server). The Client Access server is a thin and stateless server that doesn’t do any data rendering. There’s never anything queued or stored on the Client Access server.
    So, I recommend you try to modify the permissions on default hub transport receive connector, it may achieve your requirement .
    Best regards,
    Niko Cheng
    TechNet Community Support

  • Prevent callers from leaving VM for uninitialized mailboxes?

    I'm pretty certain that I know the answer to this question but I'll put it out there...
    Does anyone know of a setting in Unity Connection that would prevent callers from leaving voice messages in uninitialized mailboxes?
    Scenario:  Admin creates a new subscriber mailbox for John.  Before John is able to set up his voicemail, he receives a call and the caller is forwarded to his VM.  At this point, you want to prevent the caller (via Unity Connection settings) from leaving a message for John.
    I haven't seen any system level settings that would provide that functionality.  Anyone know of something I'm missing?
    Hailey

    Hailey-Man,
    Hope life is treating you my friend! Just think Spring is
    not too far off, so you'll be back on the open road
    There is no setting that I've found that sets this like in the
    "old" Octel days...hahahahahahaha! We use this method on occasion.
    It's not perfect but it does work.
    On the Template for the Users you are creating;
    We leverage the Alternate Greeting > No End date and time >
    Callers hear System Message > after Greeting action "Hang up"
    This works like the uninitialized set up used to in Octel wherein no
    messages can be left. Once the User goes through the First Time
    Enrollment the Alternate Greeting must be turned off.
    Cheers!
    Rob

  • How to prevent user from deactivating the adobe software

    I am working in a training center, We've got 20 machines here installed with Adobe CS3 production premium (not using network license). The problem now i foresee is the software deactivate problem, i found user can deactivate the adobe software even they dont have XP administrator rights.
    And what i know about activation of adobe software is that there is a limit of activation count of 30 tries and after that i have to call the adobe technical support for help.
    Is there any way that i can prevent user from deactivating the software in terms of registry modification or what other kinds of method.
    Thanks
    Ivan

    If you have 20 machines I assume you have a volume license, which does not require de/activation anyway.
    If you have 20 separate licences... well, the only thing I can think of is to block the Adobe Activation domains of adobe.com through the firewall of your network. You should probably contact Adobe directly for more specific info.

  • HT1923 In trying to delete the Apple file in the Program/Common File I can delete all contents except the Internet Services folder.  Thus preventing me from deleting the Apple FIle.  Error message says I need permission to delete this file.  How do I proc

    Trying to delete the Apple Folder from Program Files/Common Files.  I can delete all the contents except for the Internet Services folder which prevents me from making the deletion.  The error message says "you need permission to delete this file".
    Discovered this problem when trying to upgrade from my 3G iPhone to a new 5S iPhone unsucessfully.

    See note 3 of Troubleshooting issues with iTunes for Windows updates.
    tt2

  • How can i prevent mail from downloading the same messages over and over again?

    is there any way to prevent Mail from downloading the same messages over and over again? Mail has a minimum of "50 recent messages" to download, but i hate having to delete them every time i check for new mail! why doesn't the program remember if you have already downloaded a message, and suppress any subsequent downloads???

    Same issue since Mavericks.

  • I need help in resolving a problem that prevents me from accessing the iTunes store.  Message reads " iTunes cannot contact the iTunes store" and also says that my laptop is no longer authorized to access my account.  Help!

    I need help in resolving a problem that prevents me from accessing the iTunes store.  Message reads " iTunes cannot contact the iTunes store" and also says that my laptop is no longer authorized to access my account.  Help!

    Go up to the top of your screen on iTunes and click on 'Store'.  Then go down to 'Authorize This Computer'.  That should cover part of it unless you've already authorized a bunch of other computers to use your account.  If that's the case, you'll have to go to one of those computers and click the button just below it to 'deauthorize your account' from that computer.  If you're not able to access the store, check your internet connection to make sure you are connected.  Hope this helps.. good luck!     

  • Captivate 5: is there a way to prevent someone from taking the quiz, without going through the conte

    Hi.
    Is there a way in Captivate 5 to prevent someone from clicking on the quiz to take it, without having gone through the content?
    CB.

    Hi.
    Regarding preventing someone from taking the quiz without going through the content...
    I decided to separate the quiz out of the project as a separate item.
    We are going to use a Learning Management System which will house the module to control the access.
    The LMS can be set to not allow people to click on the Quiz link, until they have gone through the content.  (So they cannot by-pass the content and just do the quiz).
    I was trying to find a way to control this from within Captivate 5 and keep people from being able to click on the quiz without going through the content. (And keep the quiz inside the original project).
    However, this LMS solution will work for this module.
    Thanks everyone!
    CB

  • Is there a way to prevent AnyConnect from caching the username of the last person who connected to the VPN?

    Is there a way to prevent AnyConnect from caching the username of the last  person who connected to the VPN?

    This can be done via specifying the "RestrictPreferenceCaching" parameter as described in the Anyconnect Admin Guide here:
    By design, AnyConnect does not cache sensitive information to disk. Enabling this parameter extends this policy to any type of user information stored in the AnyConnect preferences.
    •Credentials—The user name and second user name are not cached.
    •Thumbprints—The client and server certificate thumbprints are not cached.
    •CredentialsAndThumbprints—Certificate thumbprints and user names are not cached.
    •All—No automatic preferences are cached.
    •false—All preferences are written to disk (default—behavior consistent with AnyConnect 2.3 and earlier).

  • I've been giving HD videos in MTS format and convert the for editing in FCE.  Looks good in the program, but when I export the finished film, quality had been noticeable diminished.  Is there any way to prevent FCE from lowering the output quality?

    Hello -
    I've been sent HD footage in MTS format and converted it to Mp4 for editing in FCE.  It looks good in FCE but when I export the movie, the quality is noticably diminished.   Is there any way I can prevent FCE from lowering the quality on export?
    Thanks.

    >I use Foxreal video converter for Mac to convert the MTS using the Apple intermediate codec setting and the problem is that I don't get image, just audio
    My thought would be to NOT use Foxreal video converter.
    Use MPEG Streamclip or Clipwrap.
    -DH

  • Is it possible to prevent users from using the ''Purge'' option from the ''Recover deleted items'' in Office 365?

    Hi,
    After speaking with a Microsoft engineer over the phone, I've been told that there is no way to prevent users to go to their OWA and manually Purge specific items from the ''Recover deleted items''. The Microsoft tech told us to place the desired mailboxes
    on a litigation-hold and that all data will be recoverable... but only from the time you place the mailbox onto Litigation-Hold and previous items, which doesn't take effect for new-coming emails. 
    1- From what I understand, any new items coming in the mailbox after the Litigation-Hold is put in place will still be ''purgeable'', right?
    2- Is there a way (PowerShell, Security group, etc.) that can prevent a user from using the Purge option?
    We are very surprised that there is absolutely no thread that talks about this issue, which in our opinion, is a major legal and security flaw from Office 365. This is a main concern for us to actually go with Office365. For instance, this means that at
    any given time, if a user exchanges emails with a competitor, they can manually purge emails sent and receive as soon as it is sent/received, even after Litigation-Hold is in place.
    Thank you for your reply and let us know if you have more questions.
    Normand Bessette, IT support technician, Newad Media

    Thank you for the reply.
    Is there still a way to prevent users from using the Purge option, like with a Powershell script to disable Purge?

  • Stop the cursor from leaving the frame/panel?

    Im making a simple target game where you shoot targets with the mouse. What I'd like to do is stop the mouse cursor from leaving the panel/frame. I've tried moving the cursor there with the Robot class, but 1) it doesnt lock it directly to the edge, 2) it doesnt stop at the top edge and left edge, 3) the bottom edge results in the cursor being placed in the wrong place and finally, 4) if u move the cursor fast enough it breaks out anyway :(
    Hope someone can help,
    Thanx.

    Wow nice responses. I have two questions:
    1) What is native code?Write the code to capture the mouse in C/C++ (Windows supports capturing the mouse cursor - dunno about linux or solaris), then write a JNI wrapper function so you can call it from within Java.
    >
    2) Is it difficult to make it full screen? I was
    thinking of doing that but the thought of rescaling
    everything (i.e. fonts, images etc) made me think
    otherwise.Fullscreen is easy, simply graphicsDevice.setFullscreenWindow(window);
    Once in fullscreen, you can change the resolution to whatever you like (limited to what is supported by the gfx card ofcourse :p), so you shouldn't have to worry about rescaling gfx 2much.
    >
    Thanx,
    Jon

  • View/Change User Accounts From Across The Network - Do not have Server

    Is there a program or utility that can be run in Mac OS X Tiger or Leopard to manage user accounts on other Macs that are located across the network? Is there anything that will do this that is free, or not too much money?
    Our setup: multiple Macs on a network that is primarily a Windows AD Domain. For various reasons, we do not have the Macs setup as members of AD. We also do not have a Mac OS X Server. I am wondering if there is something that is built-in, free, or on the cheaper-end, to manage user accounts and their permissions from across the network on the Macs?
    Thank you for your help!
    Dan

    If the systems are not bound to a parent domain, then local account policy will need to be set individually. There is a way to get Workgroup Manager working on OS X client, but I do not know of a way for it to see remote NetInfo/DS Local data stores. It will only see the local store. NetInfo in the 10.2 days could pull this off. But Apple removed those features in favor of LDAP and eventually DS Local.
    You will probably need to use a combination of tools. Start with defining base settings in the User Template to ensure that all new home folders are created equal. Then use ARD or ssh to define user policy with pwpolicy and other tools like niutil (Tiger) or dscl. Test with mcxquery. If you get Server Admin Tools, you can use Workgroup Manager to craft the needed xml for mcx values, then inject into the user account.
    But this is only going to get you local policy. If users are connecting to file shares and mail, they are using their network credentials so those policies need to be managed at the domain level.
    I would encourage binding the machines to the domain. While this can, and has (sadly), been done, being part of the domain is so much easier. If you need a system for storing the LDAP schema, get a Mini and do it on the cheap. Otherwise, consider AD schema modification and then practice your xml skills.
    Hope this helps

Maybe you are looking for

  • The Web template does not exist in the master system

    We are using a Web Template (ZPORTAL) as an access point to other web templates and to 0ANALYZER. We recieve an abort when the use logs on for the first time and is presented with the password change window. When they change the password and click ok

  • How do I change media start timecode?

    I'm working on a project that was handed to me after a significant amount of capturing had already been done. Much of the footage (I'm praying that not all of it is like this) was captured using Capture Now, so there is no room left for pre-roll on a

  • Adobe Indesign does not recognize FONTEXPLORER X for indesign cc.pln as a valid plug-in.

    I got this error after installing Indesign CC 64bit  and font exploer x on Windows 8. After unistalling both apps a couple times then re-installing i loaded some additional fonts via font explorer then activated them and started a document and the fo

  • Issues With Adobe XI Printing

    I recently installed Adobe XI on my desktop (Win 7), and am having issues with printing. If the printing size is set at 100%, the only pages that print are the first and last page of some pdf documents. With other pdfs, I have to resize it to 76% for

  • Error in while creating sms

    i am getting an error message "memory full .  close some applications and try again" when im creating message directly from the call dial list. all my applications are closed still im getting this error.