Sun Nov 03, 2013 10:47 pm
I seem to have an issue whereas some clients on my network have become infected with a dnsbot. My firewall filter rules specify the ports used and to "add src to address list" , naming the list "virus2" with a following rule to tarpit it. However , no list is ever generated to enable me to track the source. Am I missing something here to catch the offending culprit?It counts the traffic , it just doesn't tell me where from.