04-10-2018 08:19 AM
Hello all,
I am wondering if there is any way to let's say block the IP address from a source for a set period of time. An example of this could be, we are being attack, same IP address hitting our firewall a 100 times in 3 minutes, It is being reported as "code execution vulnerability." Now the action is dropped, but the IP address could be running some other exploit at the same time, and not recognized by the firewall as such or maybe it is. I am looking for a way to automate a process by which we can setup some kind of rule to block that IP address, of the source, for a set period of time.
Basic I am looking for a way to say look I am being hit by this IP on multiple ports and they are for different services all with let say 2 minutes. I want to be able to automatically block that source for let say 5-10 minutes to see if it happens again and if it does the add it to the external block-list.
Any assistance would be greatly appreciated.
04-10-2018 08:28 AM
You can do this by configuring a Threat Exception and changing the Action to block-ip.
You can define the block time for the block-ip action.
Here are a couple KB's on this subject:
04-10-2018 08:28 AM
You can do this by configuring a Threat Exception and changing the Action to block-ip.
You can define the block time for the block-ip action.
Here are a couple KB's on this subject:
04-11-2018 12:23 AM
With Block-IP you can drop traffic for a defined period, between 1 and 3600 seconds. Take care when apply because legitimate sources could also be blocked.
02-22-2021 10:58 AM
This maybe of use to you.
check it out.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!