> >what i can't really understand is, why bother making a tool like > >this, if you are afraid that it is going to be used, or that someone > >will ssh scan you from taiwan? so let's just block all the non us > >countries or what? > > I'm not afraid that it's going to be used. I _want_ it to be used, > I never suggested otherwise. I'm not blocking "non-US" countries, I'm > blocking "shitholes". The more people blackhole shitholes, the better > off the world is in the long run, this provides shitholes with an > incentive to no longer be shitholes. ("What do you mean, I can't
through the magick of PF's ordered filtering, you could allow all inbound on port 80, and THEN block your desired ranges.