- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Block traffic coming from known malicious IP a...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Block traffic coming from known malicious IP addresses
How can we block traffic coming from known dynamic list of malicious IP addresses using SmartConsole? (Not through the ssh console as described in sk103154)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As far as I know, there is no SmartConsole way to do this currently.
This is planned for later releases.
As an alternative to sk103154, you might want to look at CP Dynamic Block Lists maintained by Daniel Husand which makes use of several dynamic block lists.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a way to use this with a proxy or does it need to have direct access from the gateway? Talking about R77.30
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't believe his script supports this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Could the Indicators feature within Threat Prevention also solve this for the time being? Create a CSV of the known malicious IP's then import through SmartConsole within the Threat Prevention tab?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That's another possibility as well.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Note that IPs entered via the Indicators feature will only be used by the Anti-Bot blade, which applies only to outbound HTTP connections. Inbound connections from these IPs will not be blocked.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is that still true (outbound blocks)? According to the IOC help page at - SmartConsole R80.10 Help - You can choose to use the AV blade (the default) or AB.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello!
Thats a cool thing, is it already supported at R80.30?
Iam sorry to say i have not tried it yet ...
If you say it runs at r80.30 , or somebody has tested it successully, i will try it.
best regards
