Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[firehol_abusers_30d]: Zscaler address block in list, should be removed #273

Open
ashish-logmaster opened this issue Aug 11, 2023 · 3 comments

Comments

@ashish-logmaster
Copy link

Hi folks,
165.225.56.64
165.225.56.78
165.225.56.118

Are in the lists.
The netblock 165.225.56.0 - 165.225.56.255 is owned by Zscaler which is a proxying service used by Fortune 500 companies.
I don't think you should have the above addresss in the abuse list.

[ Filing this issue as Datadog reported 165.225.56.219 in our log traffic as an abuser w.r.t to this list. They themselves have a bug of using a CIDR block for alerting vs actual info in your list.]

Thanks,

@betterthan70
Copy link

Zscaler IPs are still added in the list - how can we remove them permanently?
E.g. a lot of addresses from 165.225.206.0/23 range.

@lpriit
Copy link

lpriit commented May 15, 2024

Same issue with Zscaler 165.225.20.0/23, that it's reported as public proxy.

@william-scholes
Copy link

william-scholes commented Nov 20, 2024

Could we get this Zscaler list parsed from Json to the normal type of list in Firehol? then we can easily choose to allow or block Zscaler if we use it?
https://config.zscaler.com/api/zscloud.net/future/json
my FW doesn't natively support JSON lists so while I could parse this myself, would be useful for Firehol to include it imo

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants