This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Block IP address

Hi guys,

In my XG I see a lot of incomming tcp attempts from several IP addresses. Currently they are all blocked by rule 0. Is there a way I can create a rule that is the first in line in which I can define all the IP's I want blocked. Some sort of blacklist.

Thanks in advance.



This thread was automatically locked due to age.
Parents
  • Hi Jeffery,

    adding another rule at the top will not help much. You need to determine if they are from a specific country, then you can apply country blocking rules at the top.

    Are the failed attempts aimed at your internal devices or are they just denied connection notifications?

    Also what ACL features do you have enabled on your external interface?

    Ian

  • Hi Ian thank you for the answer. I know what you mean by country blocking but that is not the solution im looking for. In the past I applied this solution to an customer environment but that seem to block a bit more that it was meant to. Some regular websites could not be visited. Although this is my home environment now, still it doesnt feel like the right solution to me. Do you know an alternative maybe?

    The failed attempts are not aimed at any internal applications, but I see continuously connection attempts to (to me) random ports. Its like there is a port scanner active on my IP. 

Reply
  • Hi Ian thank you for the answer. I know what you mean by country blocking but that is not the solution im looking for. In the past I applied this solution to an customer environment but that seem to block a bit more that it was meant to. Some regular websites could not be visited. Although this is my home environment now, still it doesnt feel like the right solution to me. Do you know an alternative maybe?

    The failed attempts are not aimed at any internal applications, but I see continuously connection attempts to (to me) random ports. Its like there is a port scanner active on my IP. 

Children
No Data