Forum Discussion
Suggestions for dealing with SMTP brute force attacks with ASM/PSM
We are in the process of firing up a shiny new ASM solution, and in doing so one of the areas we are looking for help in mitigating is SMTP brute force login attacks. I know that the ASM (or I guess more accurately the PSM) provides a SMTP security profile configuration that has some nice options for actual mail delivery and protocol access, but nothing specific to login.
Basically what we are looking to do is very much akin to the login page security options, where we detect SMTP login failures above a certain threshold and block the IP for a period of time.
Anyone out there have any suggestions? Something I'm missing (I'm new to ASM so apologies if this is a total n00b question)? Will the ASM in learning mode be able to detect and create a policy option based on this behavior in some other part of the configuration? Something an iRule could do for us?
Thanks!
1 Reply
- Chris_Grant
Employee
Hey Tom, welcome to the wonderful world of ASM. PSM is actually part of AFM now. Our SMTP protection is not nearly as comprehensive as our HTTP protection. Your best bet for this would be to contact support (and your account team) and ask them to open a request for enhancement to add brute force protection to the SMTP security module.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com