A while back, someone asked what can stop little script kiddie hacker wannabes from trying to brute force an FTP server. I have a Cisco 2620XM router with a WIC-1ADSL, with Advanced Enterprise IOS as my edge router. I put in all the ip inspect firewall rules, and put the rule name inbound on the outgoing interface. No attempts (except anonymous, which is the only login allowed) were made. I have it logging every hour, and as soon as I did this...
Edge(config)#no ip inspect BYE_BYE ftp
the logfiles started filling up. I put it back in, and bam---problem solved.
Burt
Edge(config)#no ip inspect BYE_BYE ftp
the logfiles started filling up. I put it back in, and bam---problem solved.
Burt