On Mon, 2015-02-02 at 17:20 -0800, John R Pierce wrote:
the majority of 'botnet' systems that probe at my servers appear to be poorly configured linux servers at colocs.
They appear to be an increasing source. Those and Vietnam are currently popular. So I block the data centres/coloc IP ranges.
Blocking of individual IPs is automatic and is for all ports. It usually lasts for about 4 to 6 weeks. Manual blocking is usually of IP ranges and usually permanent but restricted to ports 25 or 80.
I want is a quiet life :-)