RE: deny access

From: David Gillett (gillettdavid_at_fhda.edu)
Date: 11/29/04

  • Next message: Gaspar de Elías: "Re: "Secure" Web Hosting?"
    To: "'Carlos Garcia'" <carlosg@cabonet.net.mx>, <security-basics@securityfocus.com>
    Date: Mon, 29 Nov 2004 09:33:08 -0800
    
    

      The canonical way to do this is with an access list, but that
    might be biting off more than you're ready to chew.
      A "quick and dirty" method is to add a black hole route for
    this address:

    enable
    config terminal
    ip route 216.212.33.185 255.255.255.255 Null0
    end
    write mem

      Your email server will still receive SYN packets when this
    address tries to connect, but the answering SYN-ACK packets
    won't make it past your router and so the connection can never
    be established. (Nor will that address get an answer to pings.)

    David Gillett

    > -----Original Message-----
    > From: Carlos Garcia [mailto:carlosg@cabonet.net.mx]
    > Sent: Wednesday, November 24, 2004 3:28 PM
    > To: security-basics@securityfocus.com
    > Subject: deny access
    >
    >
    > newbie question how can i block this ip 216.212.33.185 i have
    > a cisco 7200
    > this ip is trying to send mail with my server, i did not
    > configure the
    > router so i dont know how to do this any help?
    >
    >
    > Atte.
    > Carlos A. Garcia G.
    > Cabonet Staff
    > Tel (624) 14 30120
    >
    >


  • Next message: Gaspar de Elías: "Re: "Secure" Web Hosting?"

    Relevant Pages

    • Re: two NIC, how to configure the wanted route
      ... One router goes to the corporation email server and another one goes to the ... you add another router for the Internet ... Internet and point the email server to the corporation ip range. ... > I have 2 network cards on the PC configured as below, ...
      (microsoft.public.windows.server.networking)
    • Re: Can I use multiple internet connections simultaneously?
      ... One router goes to the corporation email server and another one goes to the ... you add another router for the Internet access ... Internet and point the email server to the corporation ip range. ... > the DSL connection is used to browse the internet? ...
      (microsoft.public.windowsxp.network_web)
    • bt connection settings - please check im not going mad
      ... a client has a BT openworld service called network 1000 Engineer Install. ... when i plug my own router in i can log in over PPPoA and the router is given ... router has port-forwarded all this email traffic to their email server. ... account is listed as dynamic. ...
      (uk.telecom.broadband)
    • Re: bt connection settings - please check im not going mad
      ... a client has a BT openworld service called network 1000 Engineer Install. ... when i plug my own router in i can log in over PPPoA and the router is ... router has port-forwarded all this email traffic to their email server. ... account is listed as dynamic. ...
      (uk.telecom.broadband)