# Fail2ban filter for kerio [Definition] failregex = ^ SMTP Spam attack detected from , ^ IP address found in DNS blacklist ^ Relay attempt from IP address ^ Attempt to deliver to unknown recipient \S+, from \S+, IP address $ ^ Failed SMTP login from ^ SMTP: User \S+ doesn't exist. Attempt from IP address ^ Client with IP address has no reverse DNS entry, connection rejected before SMTP greeting$ ^ Administration login into Web Administration from failed: IP address not allowed$ ^ Message from IP address , sender \S+ rejected: sender domain does not exist$ ignoreregex = datepattern = ^\[%%d/%%b/%%Y %%H:%%M:%%S\] # DEV NOTES: # # Author: A.P. Lawrence # Updated by: M. Bischoff # # Based off: http://aplawrence.com/Kerio/fail2ban.html