If have recently had daily port scans from the same IP, and everytime Bullguard comes up and says the IP has been banned for 600 seconds. Is it possible to make a permanent ban for this IP ?
1-When you receive the notification note down the IP address; if the notification dissapears before you can note down the IP, look in the security log taking the time as reference; 2-Go to firewall and set the user level on advanced; 3-Go to the Logs tab, Traffic log 4-Find the IP in the log in the Source Host section and right click; choose Ban>ban remote Ip address
On a related note, however, how do you tell Bullguard to STOP banning something for 600 seconds? It keeps doing this to our office's printer, so I can't print from this computer for 600 seconds whenever it happens!
Open bullguard by double clicking the clock. Click Firewall then click the Settings Tab under the check boxes look for Enable Printer and file sharing (or similar) and check it.
That should solve the printer and network problem without interupting the normal use of Bullguard's Firewall.
I having a same IP address that keeps scanning my ports. I have permanently banned it c/o Bullguard but I still get the message then the temp 600sec ban against the ip address next time it does it. Thinking maybe I hadnt banned it permanently correctly first time........i did a permanent ban again only to be told there is already a rule set up permanently banning the afore said ip.................except it hasnt!!! Any ideas?
Go to the firewall and set the user level on advanced; Doubleclick on - Custom Security tab- Notifications tab, uncheck -Display a security notification.
It can play a sound if prefer it
Please start your own thread by clicking the new topic button. Do NOT post your problem in someone elses thread.
Go to the firewall and set the user level on advanced; Doubleclick on - Custom Security tab- Notifications tab, uncheck -Display a security notification.
It can play a sound if prefer it
Yes I know how to uncheck being informed about portscan attacks but the point IM making is..........I shouldnt keep getting an alert stating that the ip address is attempting to scan my ports THEN telling me 600 secs later that "IT IS NOW UNBANNED" IF I have banned it permanently.............I am happy to be informed if somebody is scanning my ports, it keeps me alert to websites im visiting etc.. But my getting the message that the ip address is being unbanned after 600 secs is telling me that that the ip address is NOT on a definite ban as I have instructed.
I don't think that the message means that the IP address is unbanned, just that the default ban time of 600 secs has now elapsed. If you have set up an advanced rule banning it then that rule will still apply. In fact, even if there was no advanced rule Bullguard should still treat it as a new attack and ban it for a further 600 secs. I prefer to use a longer default ban time of 6000 secs as I find it cuts down on a lot of these second notifications.
Currently it is Saturday, November 22, 2008 7:30 PM (GMT +1) There are a total of 64.070 posts in 15.839 threads. In the last 3 days there were 25 new threads and 168 reply posts. View Active Threads
Who's Online
This forum has 27200 registered members. Please welcome our newest member, adbizns.com. 49 Guest(s), 1 Registered Member(s) are currently online. Details danny-boy