Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
mp2012
Contributor

ip_block script lets pass traffic during update / url fetch?

Hi,

running on R81.10 and still using the ip_block script (as in sk103154), I figured out it let traffic pass on any update. On update every 20mins, then I see packets slip through for a few seconds (logged as accepted). Anyone can confirm this?

If switching to dynamic object based ip block feature and populate it with the same data from url feed - would it change this behaviour?

 

kind regards,

mp2012

 

 

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

If I'm reading the script correctly, each time the feed is retrieved, it removes the existing SAM rules then re-creates them based on what was retrieved.
That would explain the behavior you are seeing.

Meanwhile, I believe using either a Generic Data Center object (R81+) or a Network Feed object (R81.20+) would not have the same impact.
Dynamic Objects, with appropriate scripting, might also work.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events