I use SuSEFirewall2 to block and allow connections to my server. I set specific ip addresses to connect through ssh and my mail admin application
for the world only port 80 and 25 are open. the rest is blocked.
I also run a script each day to see which URL’s try to connect my box which are logged in the firewall log
There are a few URL’s who take up about 60% of the logs
Is it possible to block them before they go trough the list of allow and deny of the firewall rules
Lets say gd.tuwien.ac.at is one of them.
drop connection before you go through the allow/deny rules of SuSEFirewall.