OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Blocking Entire Network

From: Harvey Smith (harveybuskers.org)
Date: Sat Apr 01 2006 - 05:49:02 CST


On Sat, Apr 01, 2006 at 01:01:55AM +0200, mouss wrote:
> John Beaver wrote:
> >Elijah Savage wrote:
> >>George Rae wrote:
> >>>Is it possible to block an entire network (Class C) with REJECT in the
> >>>access file.
> >>>
> >If you have to do it within postfix (i.e. no firewall available), you
> >can do this. Use the CIDR table, makes it very easy and also doesn't
> >require a postfix reload when making changes to the file.
>
> cidr does require postfix reload.

No not really, it doesn't get picked up automatically like the hash
tables, but the smtpd processes are relatively short lived.

--
Harvey