Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to block IPscan + portscan?

    Scheduled Pinned Locked Moved pfSense Packages
    5 Posts 2 Posters 3.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      iamthed
      last edited by

      hello..
      i wanna ask simple question.. is there any packages that provide to block the IP scan and portscan program?

      and how to do it ??

      thx

      i'm dumb.. but i have a desire to learn

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Just dont open up any ports.
        Per default everything gets blocked.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • I
          iamthed
          last edited by

          @GruensFroeschli:

          Just dont open up any ports.
          Per default everything gets blocked.

          so u mean u do nothing for rule because it's been block anyway?
          how bout ipscan and portscan from inside network?
          is there anyway to block it ?
          i assume that u say bout "don't open up any port" it's for security from outside network?
          is it ?

          i'm dumb.. but i have a desire to learn

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            Yes this is about security against the outside.

            There is no firewall in this reality that can protect against attacks from the inside.
            How do you imagine a firewall should provide protection against traffic that never passes through it?

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • I
              iamthed
              last edited by

              hmm.. u're right..
              but i think someone must made it the protection from inside..
              statistically the attacker comes from inside  :-
              not from the outside..

              OOT i want to ask how do u know the traffic that should be blocked because it's containing virus or attacker that trying to attempt?
              how u do the monitoring?
              i've got no clue about the monitoring process which is i'm using ntop+sniffing

              i'm dumb.. but i have a desire to learn

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.