Increasing/decreasing the number of allowable connections is not a good approach, you will just compound the problem. I just got finished dealing with a clients Welchia/Lovsan worm problem and found that shaping traffic before it got to the DMZ was far more effective (using routers and firewalls) than allowing more silmutaneous connections to port 25.
In my case it was dealing with ICMP & the now infamous port 135 RPC exploit.
There is no God, only 10001010