Re: Deny large number of IPs via ipfw

2006-06-11 Thread Bill Moran
Dan Mahoney, System Admin [EMAIL PROTECTED] wrote: Hey all, I've got a file that I just synced from a major RBL, and I'd like to just use it to globally deny access to my system. Is there an easy way to do this within ipfw -- the file is about 3 *million* lines, and is from

RE: Deny large number of IPs via ipfw

2006-06-11 Thread fbsd
Using such an list of ip address from a major rbl is flawed at the core of the idea. Over 85% of those 3 million ip address are spoofed in the first place. Most are what would be called false positives. Reread the info at the source cbl.abuseat.org it says the data is not intended to be used the

RE: Deny large number of IPs via ipfw

2006-06-11 Thread Dan Mahoney, System Admin
On Sun, 11 Jun 2006, fbsd wrote: Using such an list of ip address from a major rbl is flawed at the core of the idea. Over 85% of those 3 million ip address are spoofed in the first place. Most are what would be called false positives. Reread the info at the source cbl.abuseat.org it says the

RE: Deny large number of IPs via ipfw

2006-06-11 Thread fbsd
PROTECTED] Sent: Sunday, June 11, 2006 10:43 AM To: fbsd Cc: [EMAIL PROTECTED] Subject: RE: Deny large number of IPs via ipfw On Sun, 11 Jun 2006, fbsd wrote: Using such an list of ip address from a major rbl is flawed at the core of the idea. Over 85% of those 3 million ip address are spoofed

Re: Deny large number of IPs via ipfw (fwd)

2006-06-11 Thread John L
Using such an list of ip address from a major rbl is flawed at the core of the idea. Over 85% of those 3 million ip address are spoofed in the first place. Most are what would be called false positives. Actually there are almost no false positives in the CBL. The three million addresses on