<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<oembed><type>rich</type><version>1.0</version><provider_name>phorkie</provider_name><provider_url>https://p.cweiske.de/</provider_url><title>postfix/smtpd[29302]: lost connection after AUTH from unknown[182.110.22.220]</title><author_name>Christian Weiske</author_name><cache_age>86400</cache_age><width>900</width><height>900</height><html>&lt;!-- embedding all files of https://p.cweiske.de/527 --&gt;
&lt;link rel="stylesheet" href="https://p.cweiske.de/css/embed.css"/&gt;
&lt;div class="phork" id="527"&gt;
    &lt;div class="phork-file"&gt;
 &lt;div class="phork-content"&gt;
  &lt;div class="code"&gt;&lt;pre class="txt"&gt;Dec 13 15:44:24 ahso2 postfix/smtpd[29302]: lost connection after AUTH from unknown[182.110.22.220]&#13;
&#13;
grep 'lost connection after AUTH from' /var/log/mail.log&#13;
&#13;
https://serverfault.com/a/705020/75968&lt;/pre&gt;&lt;/div&gt;

 &lt;/div&gt;
 &lt;div class="phork-meta"&gt;
  &lt;a href="https://p.cweiske.de/527/rev-raw/da3c8a6fc1162ec587944ef9f8aa29d753151d89/phork0.txt" style="float: right"&gt;view raw source&lt;/a&gt;
  &lt;a href="https://p.cweiske.de/527#phork0.txt"&gt;phork0.txt&lt;/a&gt;
 &lt;/div&gt;
&lt;/div&gt;
    &lt;div class="phork-file"&gt;
 &lt;div class="phork-content"&gt;
  &lt;div class="code"&gt;&lt;pre class="txt"&gt;$ fail2ban-regex /var/log/mail.log /etc/fail2ban/filter.d/postfix.conf &#13;
&#13;
Running tests&#13;
=============&#13;
&#13;
Use   failregex file : /etc/fail2ban/filter.d/postfix.conf&#13;
Use         log file : /var/log/mail.log&#13;
&#13;
&#13;
Results&#13;
=======&#13;
&#13;
Failregex: 6245 total&#13;
|-  #) [# of hits] regular expression&#13;
|   1) [163] ^\s*(&amp;lt;[^.]+\.[^.]+&amp;gt;)?\s*(?:\S+ )?(?:kernel: \[ *\d+\.\d+\] )?(?:@vserver_\S+ )?(?:(?:\[\d+\])?:\s+[\[\(]?postfix/smtpd(?:\(\S+\))?[\]\)]?:?|[\[\(]?postfix/smtpd(?:\(\S+\))?[\]\)]?:?(?:\[\d+\])?:?)?\s(?:\[ID \d+ \S+\])?\s*NOQUEUE: reject: RCPT from \S+\[&amp;lt;HOST&amp;gt;\]: 554 5\.7\.1 .*$&#13;
|   5) [6082] ^\s*(&amp;lt;[^.]+\.[^.]+&amp;gt;)?\s*(?:\S+ )?(?:kernel: \[ *\d+\.\d+\] )?(?:@vserver_\S+ )?(?:(?:\[\d+\])?:\s+[\[\(]?postfix/smtpd(?:\(\S+\))?[\]\)]?:?|[\[\(]?postfix/smtpd(?:\(\S+\))?[\]\)]?:?(?:\[\d+\])?:?)?\s(?:\[ID \d+ \S+\])?\s*lost connection after AUTH from \S+\[&amp;lt;HOST&amp;gt;\]$&#13;
&lt;/pre&gt;&lt;/div&gt;

 &lt;/div&gt;
 &lt;div class="phork-meta"&gt;
  &lt;a href="https://p.cweiske.de/527/rev-raw/da3c8a6fc1162ec587944ef9f8aa29d753151d89/testing.txt" style="float: right"&gt;view raw source&lt;/a&gt;
  &lt;a href="https://p.cweiske.de/527#testing.txt"&gt;testing.txt&lt;/a&gt;
 &lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
</html></oembed>
