April 6, 2023, 9:27 a.m. | /u/McBeano72

cybersecurity www.reddit.com

Quite often we'll add the public IP's to a blacklist that we see persistently triggering alerts. The thing is, the firewall threat prevention/IPS is blocking their attacks anyway. And often the source IP's are just too numerous to keep blacklisting them.

So it feels like a futile activity really. Chances are they'll be attacking/scanning from different IP's in the near future anyway.

Then of course there is the possibility an IP you blacklisted is used by a legitimate source in …

alerts attacks blocking course cybersecurity doing firewall future ips malicious near perimeter prevention public scanning threat threat prevention

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

EY GDS Internship Program - SAP, Cyber, IT Consultant or Finance Talents with German language

@ EY | Wrocław, DS, PL, 50-086

Security Architect - 100% Remote (REF1604S)

@ Citizant | Chantilly, VA, United States

Network Security Engineer - Firewall admin (f/m/d)

@ Deutsche Börse | Prague, CZ

Junior Cyber Solutions Consultant

@ Dionach | Glasgow, Scotland, United Kingdom

Senior Software Engineer (Cryptography), Bitkey

@ Block | New York City, United States