Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Permanently Blocking Obvious Attack Attempts

Hi there,

I'm wondering if the functionality exists to blacklist IP addresses based on the destination port that they attempt to connect to our UTM (9.4) with.

For example, we've just set up our UTM on a temporary ADSL net connection while migrating and tuning our rules prior to migration to a production environment.

I'm seeing a constant flow of connection attempts to ports which are obviously attempts to compromise the system - eg port 22 and 23, random high RPC ports and others like DNS etc. This traffic is obviously dropped, and the connection attempt is logged.

We would only ever intend to publish a very strict set of ports externally, for example https.

Is there a way to automatically blacklist IP addresses that attempt to communicate with the UTM on ports which are intended as attack ports? It seems logical to me that if an IP address has attempted to communicate over SSH then in future it should be prevented from communicating with any published ports as well (like https, which would otherwise be permitted).

Thanks!



This thread was automatically locked due to age.
  • Hi, Tim, and welcome to the UTM Community!

    Check #1 in Rulz - a "blackhole DNAT" is what you want.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
  • Thank you and sorry for taking so long to respond - I did look into this immediately after you suggested it (and read all of the Rulz)!

    I was mainly wondering if there was some mechanism that could locally and automatically blackhole malicious senders. Perhaps it's an ideas thread question? As I do not want to be manually adding IP addresses to a blackhole dnat when they're obviously attempting to connect in illegitimate ways.

  • Yes, I believe that you will find that suggestion in Ideas, Tim.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?