Firewall Wizards mailing list archives

How do you fight an attack in progress?


From: "Grigorof, Adrian" <agrigoro () mobility com>
Date: Fri, 19 Sep 1997 11:21:45 -0400

Hello everybody,

As the subject line suggests, I'm interested to find how do you fight an
attack in progress. Let's say that your firewall keeps sending you
messages about a scan in progress or something similar. You have the IP
address. You look-up the domain, call the administrator that you found
for that domain and get just a voice mail or a "number disconnected"
message. Worst case: there is no domain associated with that IP address.
The firewall keeps paging you and your adrenaline level grows
exponentially.

So, how do you Wizards deal with such situations? 


Adrian
Apprentice Wizard



Current thread: