IP Address Blacklist usage

Status
Not open for further replies.

Avram Grossman

Customer
Joined
Jan 5, 2019
Messages
40
Reaction score
2
it doesn't take long for the hackers to spread the word of a new SIP system on the internet. We went from one or two a week to 15 per day.
The Blocked IP Address is catching the "Blocked for too many failed authentications." This is good.
However, I converted the 'common' denominator IP Address into a more global block, using the "Add Range" example:
6.65.0.0 should block all Class D & C addresses. 6.65.0.0 subnet 255.255.0.0

While it is still blocking anything from 6.65.xxx.xxx, the display shows the full IP address that was blocked added to the list after the failed attempts are reached.

Is the "range" IP Block NOT blocking the first attempts of anything within the sub-class range?
I have the expiration dates set to a few years from now.
 
And why is the door wide open?
Every need is different obviously, but I block all external requests to register.
Remote phones In an office were previously allowed by public IP, but now are on a Site2Site VPN.
Smart devices are using port 5090 Tunnel.
 
It sounds like you edited an existing entry. That generally doesn't work. Make a brand new entry for the range you want to block or better yet subscribe to the global blacklist and use your time for something more productive.
 
Ah. I'm still on Ver 15 which does not (I don't see it) the Automatic Global... Thanks.
 
if you have a commercial license, then you can upgrade to v16 for free
 
Status
Not open for further replies.

Forum statistics

Threads
111,934
Messages
589,819
Members
164,811
Latest member
aurorasigntrtechitnet