This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Attempting to block IP generating portscan and intrusion alerts

ASG 220 with 7.201.
A particular IP address has been generating a lot of port scan and intrusion alerts (Message........: WEB-IIS iisadmin access)
It's filling up my inbox so I thought I would just drop all packets from that IP with a pf rule (Source the ip, service, any, destination, internal network) but I am still getting periodic floods of alerts.

Whats the best approach to these issues anyway?


This thread was automatically locked due to age.
Parents Reply Children
  • Yes, the IPS alerts have gone away. I am used to seeing port scans from China, Belgium and places like that. THis one was from the USA and I just found out it was from a legit security company hired to do penetration testing unbeknown to me.