- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-10-2018 08:19 AM
Hello all,
I am wondering if there is any way to let's say block the IP address from a source for a set period of time. An example of this could be, we are being attack, same IP address hitting our firewall a 100 times in 3 minutes, It is being reported as "code execution vulnerability." Now the action is dropped, but the IP address could be running some other exploit at the same time, and not recognized by the firewall as such or maybe it is. I am looking for a way to automate a process by which we can setup some kind of rule to block that IP address, of the source, for a set period of time.
Basic I am looking for a way to say look I am being hit by this IP on multiple ports and they are for different services all with let say 2 minutes. I want to be able to automatically block that source for let say 5-10 minutes to see if it happens again and if it does the add it to the external block-list.
Any assistance would be greatly appreciated.