Hi Guys:
I have a Cisco Ironport Cluster with C370 & C670 devices, I have seen many Potential Directory Harvest Attack detected 3 days ago and some guys got affected during that event. We finally found out the MTA Client involved in this situation and the domains, and we need to know the following in order to take some action.
1.- Is there aby document that mentions the best practice for DHAP, I meant 10, 25, unlimited (default), etc ?
2.- How long does it take to setup again the SMTP connection with the involved MTA, 10, 20 minutes ? or on whom it depends on ? ESA or MTA client ?
Thanks a lot guys, I´d really appreciate your help.