Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    Member
    Join Date
    Dec 2007
    Posts
    70

    Default Apple Macs trigger IP blocks - port 587

    Hi there

    We have port 587 (Mail Submission) closed but apple macs keep scanning it resulting in LFD blocks. This message in /var/log/messages is typical:

    Jun 4 12:29:28 ns10 kernel: Firewall: *TCP_IN Blocked* IN=eth0 OUT= MAC=00:15:c5:e9:c3:2d:00:1c:0f:5c:d1:00:08:00 SRC=109.180.184.92 DST=195.238.172.13 LEN=64 TOS=0x00 PREC=0x00 TTL=47 ID=23013 DF PROTO=TCP SPT=51194 DPT=587 WINDOW=65535 RES=0x00 SYN URGP=0

    triggering in lfd.log:

    Jun 4 12:29:28 ns lfd[32662]: *Port Scan* detected from 109.180.184.92. 11 its in the last 192 seconds - *Blocked in csf* for 3600 secs

    This produces irate customers.

    Can the 587 scan be switched off easily in Apple clients? Annoyingly they seem to try 587 first by default. What are the ramifications of opening 587 in the CSF firewall if that will help?

    TIA
    Dude

  2. #2
    Member sawbuck's Avatar
    Join Date
    Jan 2004
    Posts
    1,313
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Don't know about turning off access to 587 in Mac email clients but 587 is generally seen as a useful alternative if 25 is blocked, by an ISP for instance.

    Do you have 587 blocked for a particular reason?

  3. #3
    Member brianoz's Avatar
    Join Date
    Mar 2004
    Location
    Melbourne, Australia
    Posts
    1,117
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    This probably needs to be discussed at the configserver forums rather than here.

    I've seen customers blocked by this and it's a real problem - possibly solvable by running something useful on that port!

  4. #4
    Member
    Join Date
    Oct 2003
    Posts
    57

    Default

    You could make use of the cPanel option "run a second instance of Exim on another port" option found under the "service manager" menu in WHM - "exim on another port". Enter 587 in the box, check "enabled" and "monitored" and click "save" at the bottom.

    You should find improved email connectivity for not only Mac users but MS Outlook clients as well.

    Be sure to add port 587 to your allowed ports in your CSF configuration.

Similar Threads & Tags
Similar threads

  1. Apple Macs trigger IP blocks - port 587
    By BigLebowski in forum Security
    Replies: 0
    Last Post: 06-04-2010, 06:54 AM
  2. smtp on port 587
    By bejbi in forum E-mail Discussions
    Replies: 2
    Last Post: 12-19-2007, 10:25 AM
  3. Mailscanner with exim port 587?
    By dory36 in forum cPanel Developers
    Replies: 1
    Last Post: 06-08-2007, 10:48 AM
  4. Port 587
    By sparek-3 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-19-2006, 04:10 PM
  5. Use port 587?
    By vauge in forum New User Questions
    Replies: 3
    Last Post: 03-13-2005, 07:39 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube