Need to ban IP address for port scanning or multiple failed ftp/rdp logon attempts

Discussion in 'Networking' started by imported_nunya, Dec 13, 2007.

  imported_nunya

    imported_nunya

    So I've been on the phone and web all day now trying to find a piece of hardware or software to do this. I need something that will recognize a port scan and block that IP, and also recognize repeated ftp/rdp logon attemps and block those. I'm looking for something under 1k, so far the only things I've found are a 5k cisco box and a 9k juniper box. If anyone has a suggestion I'm open to just about anything.
  James Bond

    James Bond

    Why not just keep all ports blocked that aren't being used?

    Is it always coming from the same IP?? If so, just deny that IP in your ACL.

    It would help if you gave more information -- How is the network set up? Is this some home network with a SOHO router, or a corporate, or what?
  skyking

    skyking

    move the router remote management port to a higher nonstandard port, and protect it with a strong password.
    Only open ports when you need to use them.
  spidey07

    spidey07

    This is what is known as Internet background noise.

    Some more details would be helpful.

    In otherwords, what are you really trying to do here and what is the network evironment.