Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Need to block IP's

Status
Not open for further replies.

rtiv

IS-IT--Management
Mar 12, 2002
142
US
Due to spam, I need to block the following IP's from entering my network. I have a PIX520. What would the commands be ? Thanks

internet address = 208.177.184
64.79.64.7
internet address = 64.79.64.8
 
I added these entries, are they correct:

conduit deny tcp any host 208.32.232.12 (hitcnt=0)
conduit deny tcp any host 208.177.184.28 (hitcnt=0)
conduit deny tcp any host 64.79.64.7 (hitcnt=0)
conduit deny tcp any host 64.79.64.8 (hitcnt=0
 
just upgraded to 6.1(3) last week. Will start using access lists. What would be the correct access list statement in this case ?

Thanks
 
HI.

* Since SPAM goes directly to your email server, you have also the alternative to block it there instead of the firewall, whatever seems better (If there are many smtp server behind the pix this is of course not a good option).

* For access-list syntax and other info, see the following:

Bye
Yizhar Hurwitz
 
Ok, I need to prevent any host on network 81.9.8.0 from coming into my PIX. What would the statement be ?

conduit deny ip any host 81.9.8.0

????
 
Almost.
For a network, you should define the subnet mask, like:

conduit deny ip any 81.9.8.0 255.255.255.0

It's all written here:

Check out this note:
"The conduit command statements are processed in the order entered into the configuration. "

So you might need to clear and re-enter (or paste) all conduit commands in the order you want.

Bye
Yizhar Hurwitz
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top