- 论坛徽章:
- 0
|
在网关的路由器里面禁止该IP,失败
2621#sh access-lists
Standard IP access list 1
permit 192.168.10.0, wildcard bits 0.0.0.255
permit 192.168.1.0, wildcard bits 0.0.0.255
permit 192.168.30.0, wildcard bits 0.0.0.255
permit 192.168.40.0, wildcard bits 0.0.0.255
permit 192.168.50.0, wildcard bits 0.0.0.255
permit 192.168.60.0, wildcard bits 0.0.0.255
permit 192.168.70.0, wildcard bits 0.0.0.255
permit 192.168.80.0, wildcard bits 0.0.0.255
permit 192.168.90.0, wildcard bits 0.0.0.255
permit 192.168.20.0, wildcard bits 0.0.0.255
Extended IP access list 102
permit icmp any any unreachable
permit icmp any any administratively-prohibited
permit icmp any any packet-too-big
permit icmp any any time-exceeded
permit icmp any any echo-reply
Extended IP access list 103
deny ip host 221.133.204.4 any
deny ip host 117.63.28.113 any
deny ip host 124.118.23.180 any
deny ip host 58.218.35.224 any
2621#
在服务器里面用iptables直接drop该ip,失败
iptables -A INPUT -s 117.63.28.113 -j DROP
[root@mail httpd]# iptables -A INPUT -s 124.118.23.180 -j DROP
[root@mail httpd]# iptables -A INPUT -s 58.218.35.224 -j DROP
再查看web日志,access里面仍然有大量的:
117.63.28.113 - - [12/Aug/2008:13:00:39 +0800] "GET / HTTP/1.1" 200 38652
58.218.35.224 - - [12/Aug/2008:13:00:40 +0800] "GET / HTTP/1.1" 200 38652
124.118.23.180 - - [12/Aug/2008:13:00:39 +0800] "GET / HTTP/1.1" 200 38652
124.118.23.180 - - [12/Aug/2008:13:00:39 +0800] "GET / HTTP/1.1" 200 38652
58.218.35.224 - - [12/Aug/2008:13:00:41 +0800] "GET / HTTP/1.1" 200 38652
58.218.35.224 - - [12/Aug/2008:13:00:35 +0800] "GET / HTTP/1.1" 200 38652
为什么防不住啊? |
|