    how to block an ip

    How can I block an ip serverwide? Can I just add it to apf?

    You can deny ips entirely through APF with the -d flag. /locationofapf/apf -d ip optionalnote. This will block the ip immediately and add it to the deny_hosts file for APF to block it permantently.
    iptables -I INPUT -s -j DROP
