Create a Blacklist

Hands-On Lab


The aim of this lab is to create a blacklist with firewalld. A blacklist can be populated with any set of IP addresses that are either downloaded lists from the internet, or custom created blacklists by you, or a combination of both. When populating a blacklist of your own, you can do it by gradually adding a certain amount of IP addresses in a period of time, that way expanding the list. First you need to examine the log files and see who has been making requests, then examine these requests. If the requests seems malicious or for some reason you do not want it to send you any requests, all you have to do is add the IP address to the list. After some time you will notice that there will be a decrease in the number of malicious requests, but they will never completely stop.

