How to block an IP address on FTD based on Priority and Classification
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-12-2024 11:59 PM
Dear Community,
I am searching for a solution to automatically add the source IP of an attacker to the global block list when they perform a Priority Impact 1/2 attack.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-13-2024 03:15 AM
You can manually add the IP in to Black list or if the IP blocked security intellegence to get the feeds.
you need to find a way to manipulate using API based on the attack vector and add in to block list, that is what i am thinking my views
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-17-2024 12:51 AM
in addition what i have said before use below guide to see if that work for you.
Protect Servers from a SYN Flood DoS Attack (TCP Intercept)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-13-2024 03:32 AM
if this IP run any DDoS then try
use flexconfig and thread-detection shun
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-16-2024 10:59 PM
Can you provide me the flexconfig commands to do the same ,
Flex config is very hard to create
