<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block Cyberghost IPs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/block-cyberghost-ips/m-p/182401#M56181</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39365"&gt;@Sjoerd&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What you are asking for is essentially blocking access to every single VPN or Proxy provider, that's not a very viable solution. You might want to take a look at DoS profiles and Zone Protection limits and setup a DoS profile for the IP address that is getting hit. There really isn't a viable solution to blocking every single outside provider that someone could use to hide their IP, not to mention even if you identified the true source IP it wouldn't matter since your firewall sees the traffic coming from the listed source.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most of these types of attacks are not truly targeted, and you just got caught up in someones scripted attack. Try blocking the IP your see the traffic coming from and see if the IP changes, generally it would not.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Oct 2017 20:59:20 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-10-17T20:59:20Z</dc:date>
    <item>
      <title>Block Cyberghost IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-cyberghost-ips/m-p/182189#M56151</link>
      <description>&lt;P&gt;I see a lot of threat (thousands in a few minutes) to one of my webservers from IP&amp;nbsp;176.10.115.140.&lt;/P&gt;&lt;P&gt;This IP belongs to cyberghost, so probably someone used this to hide his own IP and attack our webserver.&lt;/P&gt;&lt;P&gt;Is there a way to block this traffic (before the threat prevention blocks it)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know I can try to block this ip (or even the scope), but when someone on the outside tries to hide his IP address when reaching my server, his intensions are probably no good.&amp;nbsp;I would like to block everyone “entering” my network who is trying to hide its IP. Is there some kind of “external dynamic list” which can help me accomplish this?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 09:44:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-cyberghost-ips/m-p/182189#M56151</guid>
      <dc:creator>Sjoerd</dc:creator>
      <dc:date>2017-10-17T09:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Block Cyberghost IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-cyberghost-ips/m-p/182401#M56181</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/39365"&gt;@Sjoerd&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What you are asking for is essentially blocking access to every single VPN or Proxy provider, that's not a very viable solution. You might want to take a look at DoS profiles and Zone Protection limits and setup a DoS profile for the IP address that is getting hit. There really isn't a viable solution to blocking every single outside provider that someone could use to hide their IP, not to mention even if you identified the true source IP it wouldn't matter since your firewall sees the traffic coming from the listed source.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most of these types of attacks are not truly targeted, and you just got caught up in someones scripted attack. Try blocking the IP your see the traffic coming from and see if the IP changes, generally it would not.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2017 20:59:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-cyberghost-ips/m-p/182401#M56181</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-10-17T20:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Block Cyberghost IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/block-cyberghost-ips/m-p/182885#M56281</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;There are dynamic lists that are publically available. Here are a few links to help out. However I think ou are looking for something that&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;suggested and that is a dynamic block. We have ours set to 3600 (seconds) so at least the attacker is blocked for one hour at a time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source on PAN support:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/54183#54183" target="_blank"&gt;https://live.paloaltonetworks.com/message/54183#54183&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sans notes on this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/" target="_blank"&gt;https://isc.sans.edu/forums/diary/Subscribing+to+the+DShield+Top+20+on+a+Palo+Alto+Networks+Firewall/19365/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Others listed on this site:&lt;/P&gt;&lt;P&gt;&lt;A href="http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt" target="_blank"&gt;http://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://malc0de.com/bl/IP_Blacklist.txt" target="_blank"&gt;http://malc0de.com/bl/IP_Blacklist.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/lists/openbl.txt" target="_blank"&gt;http://panwdbl.appspot.com/lists/openbl.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://panwdbl.appspot.com/" target="_blank"&gt;http://panwdbl.appspot.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://cinsscore.com/list/ci-badguys.txt" target="_blank"&gt;http://cinsscore.com/list/ci-badguys.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 22:01:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/block-cyberghost-ips/m-p/182885#M56281</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-10-19T22:01:03Z</dc:date>
    </item>
  </channel>
</rss>

