Greetings,
We woke up this morning to someone on the internet that's been trying to hack into our public FTP server. The person is changing to a new IP address every 3 or 4 minutes, not reuising an address at any point. They've been at it for about 5 hours now.
Looking at the logs I do see that all these attempts are coming from the same MAC address.
Can you block incoming public by MAC address? I think I read somewhere that this won't work. I created my MAC address definition and applied it to a test rule, but still see attempts coming in. (log labels these as fwrule="62007").
If not, any suggestions on how to stop these connections?
We're on a AST220 running 9.307.
Thanks
This thread was automatically locked due to age.