Question
blackhole routing
I am getting a ridiculous amount of OpenSSL.Heartbleed.Attack IPS Events. Even though they all drop I would like to blackhole the attacks from the most prevalent sources. I know that this can only be done via CLI and have begun to configure it. config router static edit 18 set blackhole enable This is where I get stuck. I know dst is required. What do I put here? I would prefer to put a FQDN if possible. Is this where the source address of the attack belongs? As I have multiple addresses, can I line list them here or do I need to create a new route for each one? TIA, Stu