41.12. Restricting Clients by IP Address

Even though it is possible to block clients from certain addresses by ensuring that they do not fall into any class, there is a feature in the module dedicated specifically to blocking clients based on their IP addresses or hostnames. This can be used to lock out specific hosts that are abusing your FTP server, or to restrict access to clients from only your own company or home network.

To define banned client systems, follow these steps:

1.
Click on the Limits and Access Control icon on the module's main page to open the form shown in Figure 41.4.

2.
Each row in the Deny access from table specifies an IP address, hostname, or pattern from which block logins. As with other tables in this module, there will always be an additional empty row for adding a new restricted address.

In the Deny from address field, you can also enter the full path to a file containing banned addresses, using negated patterns like !192.168.1.*, or even the special address !nameserved, which matches all clients that do not have a valid reverse DNS address. Only one can be entered, however—to block additional addresses, you will need to add more rows.

In the Error message file field, you must enter the full path to a file containing a message that will be sent to blocked clients. This should explain to connecting users that they have been blocked, and perhaps give a reason why.

If you want to add more than one row, you will need to save this form and reopen it so that a new empty row appears at the bottom of the table. Existing restrictions can be edited by just changing their fields, or deleted by clearing out the address.

3.
When you are done, hit the Save button at the bottom of the form to activate the new address restrictions.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.223.203.134