cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2012
Views
0
Helpful
1
Replies

Finding IP Address on the DHAP List

CBSi_Mlaun
Beginner
Beginner

I would like to find the list of IP addresses that are currently on the DHAP. Meaning which IPs are currently being blocked by DHAP and the IP addresses that have been block at any point in a given time frame. Example: the last 24 hours.

Thanks

1 Reply 1

Jeronimo Orona
Beginner
Beginner

Hello Michael,

You will find entries describing DHAP events in the mail_logs of the Cisco IronPort Email Security Appliance(ESA).

Here is an example of an entry in the mail_logs, where "DHAP" occurred.

"Tue Oct 18 00:25:35 2005 Warning: LDAP: Dropping connection due to
potential Directory Harvest Attack from host=(192.168.10.1', None),
dhap_limit=4, sender_group=SUSPECTLIST"

The following query can be used from the ESA's CLI, to look for DHAP events in the mail_logs:  

grep "dhap_limit=" mail_logs

Regards,

-Jerry Orona

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: