nanog mailing list archives

Re: ISP port blocking practice


From: "Robert E. Seastrom" <rs () seastrom com>
Date: Wed, 08 Sep 2010 15:52:27 -0400


Owen DeLong <owen () delong com> writes:

I know people at large ISPs with actual data.  Port 25 blocking is
quite effective.

Does the data show that blocking was effective, as in the host
didn't detect the block and proceed around it, or, merely that lots
of hosts try the direct approach first?

Only a single data point and a few years old, but when I was at
Inter.Net, my personal cell phone number was in the OrgTechContact for
our blocks, we blocked port 25, and my cell phone rang like three
times in a period of three years for calls regarding our netblocks.
One was for "why is this machine scanning me?", two were "why is DNS
geodata broken?".  The latter two came within days of each other so
I'm thinking news story or something.  No spam complaints.

YMMV, I'd do it again in a heartbeat though if I were running consumer
edge.

-r




Current thread: