Web Hosting Talk







View Full Version : Blocking a whole ISP


WildWayz
12-04-2001, 12:02 PM
Hi,

I keep getting Port Sentry logs showing that one ISP in particular is constantly trying to attack my server.
It ranges from trying to get in via anonymous FTP (which I disabled) and other methods.

I have emailed wandaloo.fr (the ISP) numerous times about it providing the IP, type of attack, time of attack etc and they don't reply.

So now I want to totally block out ALL wandaloo.fr visiters from coming to the server.
Is there anyway to block them without them showing on the Port Sentry logs?

Regards

James

brently27
12-04-2001, 12:24 PM
Create an access list on the router to block all it's traffic. You might need to talk to your host on this one.

WildWayz
12-04-2001, 02:30 PM
thanks :D

--James

clocker1996
12-04-2001, 06:15 PM
hah
i Get that all the time.
ftpd[2715]: connection from ANantes-101-1-3-178.abo.wanadoo.fr
ftpd[2716]: connection from ANantes-101-1-3-178.abo.wanadoo.fr

etc
I'd just do this
nslookup host.com, then block it with ipchains.
In my case, i'd do:
Name: ANantes-101-1-3-178.abo.wanadoo.fr
Address: 217.128.66.178
/sbin/ipchains -A input -s 217.128.0.0/16 -d 0/0 1:65333 -p tcp -j REJECT

davidb
12-04-2001, 06:44 PM
I get that one too a lot.

kunal
12-05-2001, 03:39 AM
i would suggest contacting the ISP first.. if that doesnt work.. contact ARIN... that should get the ISP to pull up there socks.. if it doesnt.. give the FBI a call..

WildWayz
12-05-2001, 04:58 AM
OMG - it's Kunal! :D

--James

kunal
12-05-2001, 10:29 AM
Originally posted by WildWayz
OMG - it's Kunal! :D

--James

:D

WorldNet
12-05-2001, 09:51 PM
Wow...

someone in France must be busy because I have tons of Failed Anon FTP logins from the same ISP