Solved

Having trouble denying an ip.

Posted on 2009-03-31
7
189 Views
Last Modified: 2013-12-16
I'm running linux/apache, and I'm using this to block an ip

iptables -A INPUT -s 85.158 -j DROP

But my mail filter program still says it's still getting connections from that ip, and it overwhelms the system:

Mar 31 08:37:19 [1267]: Rejected connection from 85.158.138.179:11449 (busy), ceiling is 5 slots
Mar 31 08:37:19 [1267]: Rejected connection from 85.158.138.179:55879 (busy), ceiling is 5 slots

I also use apf, and have blocked it through that,

/usr/local/sbin/apf -d 85.158.

but it's still getting through.

Any ideas on what to do or why this isn't working?

Does iptables have to be restarted or anything?  If so, how?

thanks,  Chris
0
Comment
Question by:St_Aug_Beach_Bum
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 29

Expert Comment

by:fosiul01
ID: 24028955
yes, you need to save iptables rules after inserting

then restart the iptables

0
 

Author Comment

by:St_Aug_Beach_Bum
ID: 24029041
Thank you, how do I do that?
0
 
LVL 29

Accepted Solution

by:
fosiul01 earned 500 total points
ID: 24029065
service iptables save
service iptables restart

0
Don't Cry: How Liquid Web is Ensuring Security

WannaCry is just the start. Read how Liquid Web is protecting itself and its customers against new threats.

 

Author Closing Comment

by:St_Aug_Beach_Bum
ID: 31564816
ah, thank you, that seems to have done it!  dam spammers!
0
 
LVL 29

Expert Comment

by:fosiul01
ID: 24029323
are you trying to add those Ip one by one by hand ??

then you will go mad!!

use fail2ban, or portsentry

any attemept more then 3 or 4 times, those will block those Ip automaticaly
0
 

Author Comment

by:St_Aug_Beach_Bum
ID: 24029475
Thank you, normally I don't have to, my spam program, mailstripper, takes care of things pretty well.  This was move of a denial of service type thing (I guess), just overwhelming my server with junk mail, more than it could handle, so legit mails couldn't get through.

I'll take a look at these programs right now.  
0
 

Author Comment

by:St_Aug_Beach_Bum
ID: 24029527
Not saying it was a dos attack on purpose, but the amount of spam coming from that ip had that effect on my mail services.
0

Featured Post

Why Off-Site Backups Are The Only Way To Go

You are probably backing up your data—but how and where? Ransomware is on the rise and there are variants that specifically target backups. Read on to discover why off-site is the way to go.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

rdate is a Linux command and the network time protocol for immediate date and time setup from another machine. The clocks are synchronized by entering rdate with the -s switch (command without switch just checks the time but does not set anything). …
In part one, we reviewed the prerequisites required for installing SQL Server vNext. In this part we will explore how to install Microsoft's SQL Server on Ubuntu 16.04.
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial

687 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question