Re: Stopping multiple FTP connection attempts

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance




"Jimbo" <Jimbo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:79D81006-C42A-4137-B07E-14D7EFA45960@xxxxxxxxxxxxxxxx
I have an FTP server that is getting multiple log on tries from
unauthorized
users (IE China, Eastern Europe, ect). Is there a way to block an IP
address
after several attempts.

Not with built-in tools.

I use IPSec filters (with a little script to add in new addresses) but this
requires
manually processing the log files and running the add util.

It could be automated but it involves some work.

These attacks are stopping legit users from getting
on. It is an Windows 2003 Server. The firewall is an Watchguard SOHO 6,
if
this information helps.

There are dynamic firewalls that can do these types of things.

Snort, which is REALLY an "Intrusion Dectection System (IDS) rather
than a full blown firewall, has some of this capability.

How would we "know" if a user's IP should be blocked? (I mean, if
you told me to stand there and watch it, how would I know to do it
or not, assuming I am really stupid but really good at following
instructions,
sort of like a computer <grin>)


--
Herb Martin, MCSE, MVP
http://www.LearnQuick.Com
(phone on web site)


.



Relevant Pages

  • RE: Simple Firewall: Summary
    ... Regarding IPSec filters - don't know why you desided that there's no deny ... > Are there any good tools for testing firewall performance. ... > I need a deny capability. ...
    (Security-Basics)
  • Re: Blocking outbound traffic with XP Firewall
    ... You can create ipsec filters to manage outbound traffic but they do not care ... a firewall like Zone Alarm instead or a firewall device that can have a ... "Windows Firewall doesn't prevent outbound, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Win 2003 integrated firewall enough?
    ... > protected a standalone web server. ... protection -- the slow down and limit ... The built in firewall offers virtually no extra security ... all connections on other ports with IPSec filters. ...
    (microsoft.public.windows.server.networking)
  • RE: IPsec vs any personal software firewall
    ... I agree - "IPSec filters are not a replacement for a firewall", ... You can disable default exempts by playing with registry ...
    (Focus-Microsoft)
  • RE: SP2
    ... > sucessfully run your own firewall, Norton, MaCfee, ect? ...
    (microsoft.public.windowsxp.newusers)