Security – Best way to use large IP blacklist to deny access to a Windows 2008 web server

denial-of-serviceiis-7Securitywindows-server-2008

Basically, I'm looking for a solution similar to the ones mentioned in a similar (but Linux-focussed thread) located here so that I can deny access to blacklisted IPs. I am specifically focussed on trashy form submissions to a number of publicly available websites that I host whose clients don't want CAPTCHAs. Almost every IP I've traced a bad submission to is on the various blacklists I've checked, so I anticipate knocking out the vast majority of my problems simply by denying these IPs.

I've come across 2 tools (Peerblock and PeerGuardian), but neither of their install pages mention Windows Server 2008 64-bit machines specifically.

There is an installer for Vista/Windows 7 64-bit machines mentioned on the Peerblock downloads page, but that is a little disconcerting for me for 2 reasons: 1) I would feel better if it mentioned Windows Server 2008 explicitly and 2) this leads me to believe that the software's intended use is for personal machines and I need a server-grade solution.

Anybody got software-based alternatives to recommend … or have experience with these running on 2008 64-bit boxes?

Note: I realize that a hardware firewall is a better solution, but I have an immediate need and a cost crunch on my hands.

Thanks in advance.

Best Answer

I haven't seen any apps that run on Vista 64 bit that won't run on Server 2008 64 bit (same code base) unless the vendor restricts it to workstations only. PeerBlock mentions "server variants" in the first paragraph so it's covered.

Basic IP blocking can be done in the Server firewall also but you won't have a dynamic update service.