Klaus Frank<p>Does anyone know if there is a legitimate reason that a linux system (with postfix and dovecot on it) would try to connect this AS16876 (ICANN) IP on port TCP-443?<br>"2620:0:2830:200::b:9"<br>It doesn't appear to have a Reverse DNS entry either.</p><p><a href="https://chaos.social/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://chaos.social/tags/linux" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>linux</span></a> <a href="https://chaos.social/tags/ICANN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ICANN</span></a> <a href="https://chaos.social/tags/AS16876" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AS16876</span></a></p><p><a href="https://bgp.he.net/ip/2620:0000:2830:0200:0000:0000:000b:0009" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">bgp.he.net/ip/2620:0000:2830:0</span><span class="invisible">200:0000:0000:000b:0009</span></a></p>