I'm looking at better ways to manage IP addresses that need to be blocked. Do you review and maintain them manually, run internal scripts, use firewall or security automation, or rely on an external threat-intelligence service? I'm especially interested in how people handle expiration, false positives, and different use cases such as email, web applications, and general network access.
5 Answers
We detect repeated suspicious requests, such as SQL injection attempts, on sensitive pages. After several attempts from the same address, a scheduled task adds it to a firewall block list. The list has a fixed size, so older entries eventually age out after a month or two, which is usually fine because attackers tend to move on or change addresses.
Our Palo Alto security features handle most of this through threat prevention, antivirus, and WildFire. We haven’t needed to maintain a manual blacklist in years, although that approach depends on having the budget for the platform.
For mail systems, a smart host or managed filtering provider can take care of reputation and blocking. That’s often safer than maintaining a large local list yourself.
We use a script to update the block set on our Juniper SRX firewalls nightly. If a repetitive security task can be scripted, it usually should be.
We maintain a curated list of known malicious and spam-related networks and import updates automatically each night. Security tools can also add indicators to watch-only or blocking lists, which then feed into firewall and cloud rules every few minutes. Manual maintenance just doesn’t scale well.

That’s probably the cleanest setup when the budget is available. Having the threat feeds and enforcement integrated removes a lot of operational overhead.