Hello,
(Attention: please read the following post about whitelisted entries!)
currently I was under attack from a host which was on a dns blocklist (dnsbl) but was keep on trying with about 20 connections per second. So I decided to do something against it because postscreen blocked it but produced a lot of used cpu power from postscreen as well as fail2ban. Maybe this could help someone else too:
- First I created the file /etc/fail2ban/filter.d/postfix-dnsblog.conf file containing --> https://github.com/jannickfahl…tFix/postfix-dnsblog.conf
- After that I created the following entry inside /etc/fail2ban/jail.conf:
This is banning after 10 dnsblog entries for 300 seconds (5 minutes). And for me it is saving a lot of cpu at the moment