<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block IP Subnet from FTP attack in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-ip-subnet-from-ftp-attack/m-p/1343088#M859050</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You bet. Let's assume they are coming from 75.50.95.72 /29 network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access deny tcp 75.50.95.72 255.255.255.248 any eq ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to put this above the permit FTP statement.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Jun 2009 19:47:54 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2009-06-25T19:47:54Z</dc:date>
    <item>
      <title>Block IP Subnet from FTP attack</title>
      <link>https://community.cisco.com/t5/network-security/block-ip-subnet-from-ftp-attack/m-p/1343087#M859048</link>
      <description>&lt;P&gt;Pix 501 I have a device that I 1 - 1 translate from a private to a public so it can be accessed by techs off site.  There is someone with an FTP attack on this public IP.  Is there a way to block this Subnet from accessing the device?  &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:48:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ip-subnet-from-ftp-attack/m-p/1343087#M859048</guid>
      <dc:creator>cozyk1515</dc:creator>
      <dc:date>2019-03-11T15:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: Block IP Subnet from FTP attack</title>
      <link>https://community.cisco.com/t5/network-security/block-ip-subnet-from-ftp-attack/m-p/1343088#M859050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You bet. Let's assume they are coming from 75.50.95.72 /29 network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access deny tcp 75.50.95.72 255.255.255.248 any eq ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need to put this above the permit FTP statement.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2009 19:47:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ip-subnet-from-ftp-attack/m-p/1343088#M859050</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-06-25T19:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: Block IP Subnet from FTP attack</title>
      <link>https://community.cisco.com/t5/network-security/block-ip-subnet-from-ftp-attack/m-p/1343089#M859054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Collin's way can work but what if the attacker changes their address. If possible you should get the IP addresses of the persons that are allowed to connect and change your access list to permit those addresses and block everything else.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jun 2009 17:08:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-ip-subnet-from-ftp-attack/m-p/1343089#M859054</guid>
      <dc:creator>kwillacey</dc:creator>
      <dc:date>2009-06-26T17:08:30Z</dc:date>
    </item>
  </channel>
</rss>

