Re: SSH brute forcers
Ken Connelly <[email protected]> Wed, 01 Jun 2005 20:05:46 -0500
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Merton Campbell Crockett wrote: >Everyone has ingress security policies and filters but it seems precious >few have corresponding egress security policies and filters. > >If you are not permitting CIDR blocks listed in RFC3330 into your network, >it would be reasonable not to permit packets from or to those CIDR blocks >to exit from your network. Using Cisco IOS access lists, it only takes 15 >statements to filter out RFC3330 CIDR blocks and another 24 to filter out >CIDR blocks that have not yet been assigned by IANA. > > IMHO, a better egress filter is to allow only your internal public netblock(s) to exit. - ken _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions