Thursday, May 30, 2019

Malicious behaviour from our IP addresses used by a customer

We own a /21 and /22. Depending on the services a customer takes we will provide them with a slice to do with as they see fit.

Recently one of our addresses, assigned to a customer, has been the source of repeated login attempts to a couple of routers used by our other customers.

We've locked things down more by using ACL's, but I'm wondering who is ultimately responsible for this behaviour? Is it us as the legal owner of the address space, or the customer as we have given them those addresses?

We haven't assigned directly to the customer via RIPE, as to be honest the RIPE site kills me every time I log into it.

Would we have recourse to pull these addresses from the customer if the activity continued?



No comments:

Post a Comment