Skip to content
DnsLister Forum

Where domain hunters compare notes

Custom Target Lists with Blacklisted IPs

I have a server with a few ports open which has ESET as antivirus. I noticed the ESET was blocking quite few more IPs from accessing the server than firewalla so I went down a rabbit hole of seeing what I could add to firewalla to enhanced blacklisted IPs.

I added AbuseIPDB pulling 10k IPs (since that is the most you can get with the free plan), and then all of the IPs from Blocklist.de, HoneyDB, and SpamhausDROP. I have a few tasks that update these lists automatically every 30 mins, every day, or every 4 hours depending when those lists get updated. Many of the additional lists that firewalla offer are already in other ad-blocked DNS resolvers. I have adguard home as DNS resolver too and most of the lists like HaGeZi are already there, and many of those are for outbound addresses instead of inbound from what I saw.

I was just wondering why firewalla doesn't block most of these abusive IPs? I was getting maybe 1 or 2 alerts a day about malicious IPs being blocked by firewalla but getting like 50 on the ESET firewall. This is with the IPS/IDS set to strict

Is there some else that can be done to enhance security?

Source: r/firewalla · by /u/Ok_Rate_1752

Leave a Reply

Your email address will not be published. Required fields are marked *