iptables Timed Port Block?

From: Tantor (tantor@tantor1.yi.org)
Date: 02/27/03

  • Next message: Alex Pankratov: "Re: Looking for a portable IKE library"
    From: "Tantor" <tantor@tantor1.yi.org>
    Date: Thu, 27 Feb 2003 16:08:51 GMT
    
    

    Hey all

    I'm kind of a newbie to linux, so sorry if this question is too simple.

    Basically this is what I have setup. I have a computer running Redhat 7.3
    setup to be a firewall for my network using masquerading in iptables.
    Currently I have it setup to block all external connections to the firewall
    unless they are established or related internally, except for an ftp port
    (off port 21) that accepts new, established and related connections that
    forward off to another computer on my network, and the same deal with the
    web port (port 80).

    What I want to be able to do is open port 21 and as soon as a computer scans
    that port I want something that reads its ip and drop all further packets
    from that person for x amount of time. Since nothing is using port 21 if
    something does scan it then I have to assume that its for an attack of
    somekind, so I figure it would be a good idea to just block everything from
    that IP for awhile.

    Is it possible to do that, or is there maybe a better solution? I've tried
    looking on google, but havn't really found anything that helpped me much.

    Thanks for any help you guys can provide



    Relevant Pages

    • RE: Scan for "outsider" Pcs on network
      ... If security is paramount then you would want to setup your switching fabric ... to perform MAC based restrictions by port. ... Scan for "outsider" Pcs on network ... will need to have a list of all your systems mac address. ...
      (Focus-IDS)
    • Re: A question about a basic security setup...
      ... > I have been thinking about a setup for my basic ADSL network at home that ... > before I go through motions of setting up the network. ... > I am running a web server on port 80. ... > machine for all port 80 requests. ...
      (Security-Basics)
    • Re: Newbie question. Please advise
      ... Similar to port 80 for instance. ... >firewall machine will be the public face of your network. ... which you'll have already setup on the firewall. ...
      (comp.os.linux.networking)
    • Re: cannot connect to /remote externally
      ... Les Connor [SBS MVP] ... account to a static IP account, or use another port for the server. ... > does not work for the Default Website setup in IIS. ...
      (microsoft.public.windows.server.sbs)
    • Re: cannot connect to /remote externally
      ... account to a static IP account, or use another port for the server. ... Les Connor [SBS MVP] ... does not work for the Default Website setup in IIS. ...
      (microsoft.public.windows.server.sbs)