Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
George_Ellis
Contributor

CLI Suspicious Activity Monitor for a port?

Does anyone have an example of the syntax to block a port using the fw sam command?

I use  these already.

 

Block src or dst of 94.242.249.67

fw sam -v -l long_noalert -J any 94.242.249.67

 

block any src/dst for 185.154.52.0/24

fw sam -v -l long_noalert -J subany 185.154.52.0 255.255.255.0

 

Cancel a block for a subnet 46.244.10.0/26

fw sam -v -C -J subany 46.244.10.0 255.255.255.192

 

 

 

My best guess is to block port udp/11211

 

fw sam -v -J dstpr any udp/11211

I am willing to bet that that is not right..  Anyone blocked a UDP port before?

0 Kudos
4 Replies
This widget could not be displayed.