[BlueOnyx:20549] Re: GeoIP lookup errors

Michael Stauber mstauber at blueonyx.it
Wed Jan 18 10:17:07 -05 2017


Hi Colin,

> Jan 18 10:49:27 pegasus milter-geoip: BLACKLIST: Connection (46.101.101.181) is from blacklisted country RU
> 
> Now that has rejected as a Russian address but 
> 
> http://whois.domaintools.com/46.101.101.181
> 
> It is based in Frankfurt.

I noticed something similar recently as well. An IP allegedly was from
Colombia, but in reality it was from Mexico.

There is a cronjob in /etc/cron.weekly/geoipupdate which runs this
script: /usr/bin/geoipupdate

That's supposed to update the GeoIP databases:

/usr/bin/geoipupdate
MD5 Digest of installed database is a9431605352333dff9d801f453ca0dda
/usr/share/GeoIP/GeoLiteCountry.dat is up to date, no updates required
GeoIP Database up to date
MD5 Digest of installed database is 477c74652d812fc7665ac06c1befb68b
/usr/share/GeoIP/GeoLiteCity.dat is up to date, no updates required
GeoIP Database up to date
MD5 Digest of installed database is d6cddf78f25c6413468e19af62d0c46a
/usr/share/GeoIP/GeoLiteASNum.dat is up to date, no updates required
GeoIP Database up to date

You might want to try to run that manually and see if you get any errors.

-- 
With best regards

Michael Stauber



More information about the Blueonyx mailing list