CoyoteKG
Regular Pleskian
Hello, in my syslog file I have daily hundreds logs from same IP
I check this IP, it is from Canada, and it is unfamiliar to me.
What they trying?
Can I block situation like this with fail2ban?
Code:
Jan 16 21:18:12 africka-sljiva postfix/smtpd[7950]: SSL_accept error from ip164.ip-192-99-119.net[192.99.119.164]: lost connection
Jan 16 21:18:12 africka-sljiva postfix/smtpd[7950]: lost connection after CONNECT from ip164.ip-192-99-119.net[192.99.119.164]
Jan 16 21:18:12 africka-sljiva postfix/smtpd[7950]: disconnect from ip164.ip-192-99-119.net[192.99.119.164]
I check this IP, it is from Canada, and it is unfamiliar to me.
What they trying?
Can I block situation like this with fail2ban?