- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-22-2017 02:10 PM
The difference between Block and Block IP is Block IP will stop any future communication for x seconds, while Block will only drop all traffic from the source to the destination that is actually currently open. If you are taking the time to setup DoS then utilize Block IP and keep the standard of 300 seconds once you have everything baselined. Most automated scans or attacks will move on to the next target if they don't recieve any traffic after a certain amount of time.
Allow: Permits the port scan attempts.
Alert: Generates an alert for each scan that matches the threshold within the specified time interval.
Block: Drops all traffic from the source to the destination.
Block IP: Drops all traffic for a specific period of time (in seconds). There are two options:
• Source: Blocks traffic from the source
• Source-and-Destination: Blocks traffic for the source-destination pair