[BlueOnyx:24644] Re: GeoIP quit running this AM

Larry Smith lesmith at ecsis.net
Tue Dec 15 13:41:21 -05 2020


Wow, apparenlty it hasn't been running in a while as
those last entryies are from 17 November.

How about:

systemctl restart -l milter-geoip

-- 
Larry Smith
lesmith at ecsis.net

On Tue December 15 2020 12:17, David Hahn wrote:
> [root at ds2 ~]# journalctl -l -u milter-geoip.service
> -- Logs begin at Tue 2020-11-17 21:20:03 EST, end at Tue 2020-12-15
> 13:16:29 EST. --
> Nov 17 21:24:56 ds2.pagekeeperservice.com milter-geoip[2968372]: Connect
> from IP: 111.20.200.22 - Checking if in blacklist.
> Nov 17 21:24:56 ds2.pagekeeperservice.com milter-geoip[3100839]: Connect
> from IP: 111.20.200.22 - Checking if in blacklist.
> Nov 17 21:24:56 ds2.pagekeeperservice.com milter-geoip[2968372]:
> GEOIP_CHECK: Connection from IP address: 111.20.200.22 is from country: CN
> Nov 17 21:24:56 ds2.pagekeeperservice.com milter-geoip[3100839]:
> GEOIP_CHECK: Connection from IP address: 111.20.200.22 is from country: CN
> Nov 17 21:24:56 ds2.pagekeeperservice.com milter-geoip[2968372]:
> BLACKLIST: Connection (111.20.200.22) is from blacklisted country CN
> Nov 17 21:24:56 ds2.pagekeeperservice.com milter-geoip[2968372]:
> FIREWALL: Connection (111.20.200.22) is from blacklisted country CN
> blocked via APF.
> Nov 17 21:24:56 ds2.pagekeeperservice.com milter-geoip[3100839]:
> BLACKLIST: Connection (111.20.200.22) is from blacklisted country CN
> Nov 17 21:24:56 ds2.pagekeeperservice.com milter-geoip[3100839]:
> FIREWALL: Connection (111.20.200.22) is from blacklisted country CN
> blocked via APF.
> Nov 17 21:24:56 ds2.pagekeeperservice.com sudo[4087180]:  postfix :
> TTY=unknown ; PWD=/ ; USER=root ;
> COMMAND=/home/solarspeed/milter-geoip/bin/trigger_apf.pl 111.20.2>
> Nov 17 21:24:56 ds2.pagekeeperservice.com sudo[4087180]:
> pam_unix(sudo:session): session opened for user root by (uid=0)
> Nov 17 21:24:56 ds2.pagekeeperservice.com sudo[4087179]:  postfix :
> TTY=unknown ; PWD=/ ; USER=root ;
> COMMAND=/home/solarspeed/milter-geoip/bin/trigger_apf.pl 111.20.2>
> Nov 17 21:24:56 ds2.pagekeeperservice.com sudo[4087179]:
> pam_unix(sudo:session): session opened for user root by (uid=0)
> Nov 17 21:24:58 ds2.pagekeeperservice.com sudo[4087179]:
> pam_unix(sudo:session): session closed for user root
> Nov 17 21:30:09 ds2.pagekeeperservice.com milter-geoip[2772164]: Connect
> from IP: ::1 - Checking if in blacklist.
> Nov 17 21:30:09 ds2.pagekeeperservice.com milter-geoip[2772164]:
> GEOIP_CHECK: Connection from IP address: ::1 is from country:
> Nov 17 21:30:09 ds2.pagekeeperservice.com milter-geoip[2772164]:
> WHITELIST: Connection (::1) is not in GeoIP database. Allowing.
> Nov 17 21:30:09 ds2.pagekeeperservice.com milter-geoip[2772164]:
> WHOIS_INFO: Sending MTA's FQDN could not be determined. Ignoring.
> Nov 17 21:30:09 ds2.pagekeeperservice.com milter-geoip[2772164]: Connect
> from IP: ::1 - Country code:
> Nov 17 21:30:09 ds2.pagekeeperservice.com milter-geoip[2772164]:
> WHITELIST: Connection (::1) is not in GeoIP database. Allowing.
> Nov 17 21:45:09 ds2.pagekeeperservice.com milter-geoip[2902121]: Connect
> from IP: ::1 - Checking if in blacklist.
> Nov 17 21:45:09 ds2.pagekeeperservice.com milter-geoip[2902121]:
> GEOIP_CHECK: Connection from IP address: ::1 is from country:
> Nov 17 21:45:09 ds2.pagekeeperservice.com milter-geoip[2902121]:
> WHITELIST: Connection (::1) is not in GeoIP database. Allowing.
> Nov 17 21:45:09 ds2.pagekeeperservice.com milter-geoip[2902121]:
> WHOIS_INFO: Sending MTA's FQDN could not be determined. Ignoring.
> Nov 17 21:45:09 ds2.pagekeeperservice.com milter-geoip[2902121]: Connect
> from IP: ::1 - Country code:
> Nov 17 21:45:09 ds2.pagekeeperservice.com milter-geoip[2902121]:
> WHITELIST: Connection (::1) is not in GeoIP database. Allowing.
> Nov 17 22:00:09 ds2.pagekeeperservice.com milter-geoip[2605891]: Connect
> from IP: ::1 - Checking if in blacklist.
> Nov 17 22:00:09 ds2.pagekeeperservice.com milter-geoip[2605891]:
> GEOIP_CHECK: Connection from IP address: ::1 is from country:
> Nov 17 22:00:09 ds2.pagekeeperservice.com milter-geoip[2605891]:
> WHITELIST: Connection (::1) is not in GeoIP database. Allowing.
> Nov 17 22:00:09 ds2.pagekeeperservice.com milter-geoip[2605891]:
> WHOIS_INFO: Sending MTA's FQDN could not be determined. Ignoring.
> Nov 17 22:00:09 ds2.pagekeeperservice.com milter-geoip[2605891]: Connect
> from IP: ::1 - Country code:
> Nov 17 22:00:09 ds2.pagekeeperservice.com milter-geoip[2605891]:
> WHITELIST: Connection (::1) is not in GeoIP database. Allowing.
> Nov 17 22:15:09 ds2.pagekeeperservice.com milter-geoip[2567754]: Connect
> from IP: ::1 - Checking if in blacklist.
> Nov 17 22:15:09 ds2.pagekeeperservice.com milter-geoip[2567754]:
> GEOIP_CHECK: Connection from IP address: ::1 is from country:
> Nov 17 22:15:09 ds2.pagekeeperservice.com milter-geoip[2567754]:
> WHITELIST: Connection (::1) is not in GeoIP database. Allowing.
> Nov 17 22:15:09 ds2.pagekeeperservice.com milter-geoip[2567754]:
> WHOIS_INFO: Sending MTA's FQDN could not be determined. Ignoring.
> Nov 17 22:15:09 ds2.pagekeeperservice.com milter-geoip[2567754]: Connect
> from IP: ::1 - Country code:
> Nov 17 22:15:09 ds2.pagekeeperservice.com milter-geoip[2567754]:
> WHITELIST: Connection (::1) is not in GeoIP database. Allowing.
> Nov 17 22:30:08 ds2.pagekeeperservice.com milter-geoip[2666253]: Connect
> from IP: ::1 - Checking if in blacklist.
> Nov 17 22:30:08 ds2.pagekeeperservice.com milter-geoip[2666253]:
> GEOIP_CHECK: Connection from IP address: ::1 is from country:
> Nov 17 22:30:08 ds2.pagekeeperservice.com milter-geoip[2666253]:
> WHITELIST: Connection (::1) is not in GeoIP database. Allowing.
> Nov 17 22:30:08 ds2.pagekeeperservice.com milter-geoip[2666253]:
> WHOIS_INFO: Sending MTA's FQDN could not be determined. Ignoring.
> Nov 17 22:30:08 ds2.pagekeeperservice.com milter-geoip[2666253]: Connect
> from IP: ::1 - Country code:
>
> On 12/15/2020 12:14 PM, Larry Smith wrote:
> > journalctl -l -u milter-geoip.service




More information about the Blueonyx mailing list