Re: how to drop an IP address

Spyros Tsiolis <stsiol-/[email protected]>
Newsgroups gmane.comp.security.ipcop.user
Message-ID <[email protected]>
--------------------------------------------
On Mon, 2/5/16, G.W. Haywood <[email protected]> wrote:

 Subject: Re: [IPCop-user] how to drop an IP address
 To: [email protected]
 Date: Monday, 2 May, 2016, 14:40
 
 Hi there,
 
 On Mon, 2 May 2016, Spyros Tsiolis wrote:
 
 > I was wondering how I could "drop" an IP on the red
 interface before
 > it tries to connect inside. ...
 
 Start a root shell on the ipcop box.
 
 Type the command
 
 /sbin/iptables -I CUSTOMFORWARD -j DROP -s a.b.c.d
 
 where a.b.c.d is obviously the troublesome IP address.
 
 Alternatively on some other Linux box look up the IP address
 using the
 'whois' utility (on IPCop the utility is not available, and
 like many
 others it should not be available).
 
 whois a.b.c.d
 
 This should give you an idea of the CIDR range of which the
 offending
 IP address is a part.  Then you can block the entire
 network, e.g. at
 the IPCop root shell prompt type:
 
 /sbin/iptables -I CUSTOMFORWARD -j DROP -s 24.233.0.0/19
 
 which will drop any packet in the range 24.233.0.0 to
 24.233.31.255.
 
 I took the IP address range in my example from today's
 Spamhaus DROP
 list, which I strongly recommend you look at if you haven't
 already.
 Here's a count of the packets from IPs on the Spamhaus DROP
 list which
 have been dropped in the last three months by one of my
 IPCop boxes:
 
 root@fw44d:~ #
 iptables  -L CUSTOMFORWARD -v -n --exact
 --line-numbers
 Chain CUSTOMFORWARD (1 references)
 num      pkts      bytes
 target     prot opt in 
    out     source 
          
    destination 
 1    58622148 31278545467 Spamhaus_DROP 
 all  --  *      *   
    0.0.0.0/0       
     0.0.0.0/0 
 root@fw44d:~ #
 
 Yes, that's over 58 million undoubtedly malicious packets!
 
 ....
 
 These commands will only be effective until the next IPCop
 restart or
 some other clearing of the kernel tables.  They also
 only affect the
 packets which would otherwise be forwarded by IPCop to other
 machines,
 not packets which are directed to the IPCop box
 itself.  To drop those
 you would need to add the same rules to the INPUT chain:
 
 /sbin/iptables -I INPUT -j DROP -s 24.233.0.0/19
 
 But you probably have no need to do this as IPCop would
 normally drop
 those packets anyway unless you've been very silly in
 configuring it.
 
 If you want to make the rules persist across reboots put the
 commands
 into /etc/rc.d/rc.firewall.local but beware that the
 Spamhaus DROP list
 is not static so you'll need to maintain the rules, for
 example using a
 script run periodically from the (f)crontab.
 
 -- 
 
 73,
 Ged.
---------------------------------------------------------------------------------


hi Ged,

Thank you for your much detailed reply.

One last; Does the command you suggest "play"
for RED or it doesn't matter.
Just apply it verbatim ? (excluding a.b.c.d) 

thank you kindly,

s.

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
IPCop-user mailing list
[email protected]
Manage your subscription or unsubscribe
https://lists.sourceforge.net/lists/listinfo/ipcop-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.