2 Replies Latest reply on Jul 15, 2014 9:00 AM by regie

    Black Hole Geo Location

    regie

      Hello,

       

      I know I can setup mcafee firewalls version 7 and 8 to automatically black hole individual ip addresses permanantly or for a specified period but was wondering if it is possible to black hole by geo_location. I have to log all alerts that get emailed to me and I don't set policy for the attack criteria, firewalls are set to just email not black hole if they get 5 acl denies in 30 seconds or 50 netprobes in 30 seconds. Is this common criteria? I would prefer to just block countries that I know have no legitimate reason hitting our firewalls. I apologize if this question has already been asked but I could not find anyway to search.

       

                                                             Thanks

                                                               Regie

        • 1. Re: Black Hole Geo Location
          sliedl

          You could make a Netgroup (a group of network objects) that consists of these countries that shouldn't hit your firewall (a group of geo-location objects).  Use this netgroup in a Deny rule as the Source Endpoint and set the zones to External and External; you have to set a Redirect in the rule to anything (any object) for the Deny rule to work.  Then you set up an audit filter to match this rule_name and if an IP from one of those countries hits your firewall you can then Blackhole that IP.

           

          Check out this post here I made and the other post I linked to inside this one to make the audit filter:  https://community.mcafee.com/message/172260#172260

          • 2. Re: Black Hole Geo Location
            regie

            Thank You Sliedl for the quick response and very good directions.

             

            I will now be able to pass this on to management and then start implementing it on our test firewall. This couldl take some time so I am going to mark as answered.

                                                                                        Thanks

                                                                                          Regie