Код: Выделить всё
May 25 14:35:24 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 22
May 25 14:35:24 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 14:35:45 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 22
May 25 14:35:45 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 14:38:17 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 23
May 25 14:38:17 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 14:42:15 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 23
May 25 14:42:15 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 14:49:50 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 23
May 25 14:49:50 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 14:56:26 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 22
May 25 14:56:26 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 15:01:06 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 22
May 25 15:01:06 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 15:14:37 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 23
May 25 15:14:37 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 15:29:01 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 22
May 25 15:29:01 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 15:43:47 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 22
May 25 15:43:47 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 15:54:08 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 23
May 25 15:54:08 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 16:02:39 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 23
May 25 16:02:39 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
May 25 16:04:02 freebsd2 portsentry[957]: attackalert: Connect from host: dsl-189-157-218-16-dyn.prod-infinitum.com.mx/189.157.218.16 to TCP port: 22
May 25 16:04:02 freebsd2 portsentry[957]: attackalert: Host: 189.157.218.16 is already blocked. Ignoring
и не помогу понять почему portsentry его не блочит, хотя все эти порты у него прописаны в правилах + сам лично тестил когда стучусь на 22 порт меня сразу зафорачивает на ipfw и блочит.
вот например след кадр:
Код: Выделить всё
May 25 19:43:45 freebsd2 portsentry[839]: attackalert: Connect from host: 222.186.160.50/222.186.160.50 to TCP port: 22
May 25 19:43:45 freebsd2 portsentry[839]: attackalert: Host 222.186.160.50 has been blocked via wrappers with string: "ALL: 222.186.160.50"
May 25 19:43:45 freebsd2 portsentry[839]: attackalert: Host 222.186.160.50 has been blocked via dropped route using command: "/sbin/ipfw add 1 deny all from 222.186.160.50:255.255
Вопрос почему одного заблочило, а второй продолжает спокойно долбиться по всем портам?




