|
The latency of 700ms made them giving up after 30 mins ;-)
In case of abuse or massive traffic we usually block /24 or /16 nets -
first for one hour, in case of /24 nets we block for one day.
Most (95%) is china or USA. Usually this does not hit any "good guy",
mostly it's from data centers with rented spam servers,
or from the usual provider network ranges where lots of infected PCs are
around.
Manually maintaining such lists is not easy, and trusting external lists
also has caveats (see: Spamhaus).
In the end - most automatic blocking is # of connections per source ip /
net as well as traffic shaping based on serveral rules and spread traffic
on multiple physical connections. Once we routed some SSH attackers through
our satellite links. The latency of 700ms made them giving up after 30 mins
;-)
-h
Am 11.02.2016 um 17:24 schrieb DrFranken <midrange@xxxxxxxxxxxx>:things such as Telnet, FTP, etc. We also feed some syslog data into the
In our case we'd need a bigger inbox!!! We also do this for other
process. Our blocked IP list is 10s of thousands long. I will say that once
we started blocking the hits drop off dramatically because we don't block
ports we block addresses.
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list
To post a message email: MIDRANGE-L@xxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxx
Before posting, please take a moment to review the archives
at http://archive.midrange.com/midrange-l.
Please contact support@xxxxxxxxxxxx for any subscription related
questions.
As an Amazon Associate we earn from qualifying purchases.
This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].
Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.