Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Blocking Traffic by Country on Production Networks
Timothy M. Mullen

When I originally posted to Bugtraq regarding the use of country-by-country sets to control traffic to or from any particular country, I knew that it was not a new idea. However, applying the concept for use with Microsoft's ISA Server was at least a new application for it, and apparently has had some utility for people based on the thousands of downloads that have been made of the free sets from the Hammer of God Web site.

Comments Mode:
Blocking Traffic by Country on Production Networks 2008-10-31
Anonymous (1 replies)
Re: Blocking Traffic by Country on Production Networks 2009-02-27
kurt
My firewall will go out once a week and get updates to assigned networks for countries. I would get about 50 emails a day from my firewall for ssh attacks, people running cgi, etc. I entered only China, North Korea, South Korea, and Russia to be blocked by my firewall (it blocks by country). I now get roughly 2 emails a day at most.

It might not be "PC", but why is it an issue when you're talking about the security of your server?

Excellent article, and something that all server admins should throw political correctness out the window, and take a serious look at.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/infocus/1900/1285#1285







 

Privacy Statement
Copyright 2009, SecurityFocus