    repeated hack attempts from domains not ip's and APF


    Occasionally i get hacks from domains rather than ip's and APF bans them like so:

    /etc/apf/apf -d

    However i then get repeated attempts - presumably they are able to change to a different IP, and still get in.

    There's one going on right now, so how could i setup a rule to ban * or even temporarily *.it?

    I don't believe it's possible to ban a domain or county TLD with APF.

    You'd need the IP ranges for the country and ban those.

