Telkom blocking port 25

Solar

Well-Known Member
Joined
Sep 13, 2003
Messages
112
Reaction score
0
Location
South Africa.
Hi,

Has any of you guys experienced the same problem? It seems like since about 2 weeks ago, telkom is blocking all incoming traffic on port 25. Can anyone confirm this? Try connecting to: diaria.dnip.net on port 25 and tell me if you can make a connection. If telkom IS really doing this I'm going down there to blow up some exchanges tonight.
 
No go - response is "Access to the port number given has been disabled for security reasons"
 
Blocking of port 25 is a pretty common and standard practice in North America. My ISP, for example, block all incoming and outgoing connections on port 25. (The exception is connections to port 25 to the company's own mail servers.)

By blocking incoming port 25 connections, they effectively prevent you from setting up your own mail server. In the past, people have snooped around on all 24.* IPs (all cable users in North America), looking for an unsecure mail server. Once they find one, they use it to send millions of spam messages. This is a HUGE security leak, and I can see why the cable company is blocking it. They simply can't go around making sure everyone running a mail server at home has a secure mail server that does not relay email.

By blocking outgoing port 25 connections, they prevent you from sending email through any other server except their own. This is once again a way of preventing you from spamming people to bits. They can monitor the number of emails you send, and if it exceeds say, 500 a day, they can look into it. Their goal is to prevent their mail servers and the ISP's subnet from appearing on SPAM reporting websites. You do not want all popular spam killers to block emails sent from your local net.


Initially it may be irritating, but I can see where they're coming from, and I don't mind.

<font color="blue"><b>The clock is ticking................... <i>1,174 kb/s</i> - I brake for no one</b></font id="blue">
http://home.cogeco.ca/~johannj/net_stuff/cogeco.jpg
 
I think it's pathetic. I can still run my own mail server, but now I need to make some effort. First: Find a computer on the internet where you can make a port forward from port 25 to a non-standard port, and than just relay all the mail to this non-standard port on your home server... Bloody irritating if you ask me. I WANT my own mail server. I WANT to have as many addresses as i need, and I DO NOT want to speak to some "SERVICE CONSULTANT, trying to provide me EXCELLENT SERVICE" from telkom. Really.. the guys suck... I would really like to know WHY they did this, and why they did not inform their subscribers of this when the decided to implement this last month.
When is sentech coming to cape town...?
 
Solar, Telkom never informs their customers about anything they do. It's really bad business practice to keep your customer totally in the dark. As things are going now, slowly but surely they are stopping us from doing anything with our internet connection. It's totally shocking and completely unacceptable!


----------------
United we stand!
----------------
 
Some points in no particular order of importance.

1. The email server at the office is still receiving mail fine. 2. Outgoing mail can be routed via Telkom's server as usual.
3. Some ISP's have already blocked IP's in the 165.165.xxx.xxx range (AOL for example) and this has been the case for at least a few months.

I don't see this as being a big deal at all.
 
...blocked IPs of doing what?
Sending mail? Going to sites hosted on that domain (example AOL)?

And I certainly do mind if I can do more with my dial-up connection than with my adsl...
 
I've not seen this behaviour at all. I run a stock standard SMTP daemon on my linux machine and I can directly connect to it from anywhere in the world.
 
In the war against SPAM it is quite standard to block port 25.

Quite often spammers abuse badly configured SMPT servers to relay their load without compromising their own servers - see www.ordb.org for an example of a "blacklist" for "open relay mailservers"

DSBl.org and www.spamcop.net are other examples of "blaclists" based on IP numbers.

At www.dnsrbl.net there is a "DUN" list - Dial Up Networking doing the same.

Several other lists exist.

Using lists like these most probably reduces the spam load on my server by more than 50% - even before the mail is transfered wasting bandwidth.

Telkom is actually doing you a favour by forcing you to use their SMTP servers to relay your mail to the outside world.

I just wish they would get their act together and keep their own mailservers of the RBL lists esp. spamcop!





South Africa needs World Class Broadband at World Competitive Prices.
 
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by kaspaas</i>
Telkom is actually doing you a favour by forcing you to use their SMTP servers to relay your mail to the outside world.
<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">

My thoughts exactly.

Wonder if I can convince MS Exchange to use one of those blacklists.
 
<blockquote id="quote"><font size="1" face="Verdana, Arial, Helvetica" id="quote">quote:<hr height="1" noshade id="quote"><i>Originally posted by kaspaas</i>
<br />
Telkom is actually doing you a favour by forcing you to use their SMTP servers to relay your mail to the outside world.
<hr height="1" noshade id="quote"></blockquote id="quote"></font id="quote">

erm, I don't think so. I have my own mail server with my own domain. This way when I change my service provider I'm not faced with the issue of having to change my email address. The last thing I want is to have telskum dictate to me what I services I may and may not use. Oh wait, they're already doing that with their weak attempt at the port prioritising.

If any ISP is serious about combating virii and trojans ( which usually generate quite a bit of mail ) then they should block the M$ file sharing protocol ports 135 - 139 && 445. Man, the internet will prolly be about 50% faster just from the amount of *noise* generated from these protocols being eliminated.
 
<i>erm, I don't think so. I have my own
mail server with my own domain. </i>

I also have my own mail server with my own domain - on a server outside the Telkom/SAIX network.

All the mail generated in my office is relayed via the Telkom servers on my own domain name (eg from = [email protected]) without problem.

Incoming mail I receive on my own external server, and then download it (POP3) to my internal server running FT-Gate. From there users download it again to their machines.

So you can run a mail server on your own domain even if Telkom forces you to relay via their servers.

Keep in mind, international mail don't get blocked (or slowed down infinitely) once you exceed the monthly quota this way.

The nuisance is that Telkom refuses to included a fixed IP in their ADSL package. I would much rather have received all my mail straight from the outside - it saves money. Maybe they will include a fixed IP soon, but knowing Telkom, they will price it at a rediculous level, and after a few months declare that there was no interest in the product. This is one of the +'s for Sentech.

The bad part of being forced to use the Telkom SMTP-relays, is that they do fail, are sometimes slow, and also get blocked at esp Spamcop.




South Africa needs World Class Broadband at World Competitive Prices.
 
Hello

I host my own mail server behind my ADSL / firewall setup.
Use Postfix and it works very well.
I use it daily for comms and have not experienced any port blocking.

Cheers
Bob
 
Top
Sign up to the MyBroadband newsletter
X