I'm trying to get a better handle on the latest viruses by adding some filters to our TC boxes. Basically this is what I've done thus far. I made a filter with the contents: #filter blaster.fil IP: 10 REJECT tcp-dst-port = 135; 20 REJECT tcp-dst-port = 4444; 30 REJECT udp-dst-port = 69; I uploaded it and applied it as an incoming filter on all the modems with "set int slot:1/mod:[1-24] input_filter blaster.fil filter_access on" and "enable ip address_pool_filtering". I turned on the packet logging with "set packet_logging logging all". I've tried various syslog loglevels to see if any of the filtering is working and I don't see any entries related to the filter. Any suggestions or resources I should look at? Thanks! Walt ----------------------------------------------- Walter N. Gnann ISLC, President wgnann@islc.net http://www.islc.net 843.770.1000 fax: 843.770.1002 -----------------------------------------------
participants (1)
-
Walt Gnann