You could just block anything from them except TCP on port 80.
Most of the traffic generated by the scanning will be blocked
but legitimate connections will go through.
iptables -A FORWARD -p tcp --dport 80 ACCEPT
iptables -A FORWARD -s 80.119.113.11/24 DROP
But really, you should just block anything that's not 80/TCP,
regardless of where it comes from. And drop invalid TCP packets.
And filter out IIS exploits. And enforce rate limiting.. But
then it gets a little more involved.
OK, here's a simple rule to block everything that's not 80/TCP,
regardless of the source :
iptables -A FORWARD -P DROP
iptables -A FORWARD -p tcp --dport 80 ACCEPT
--
Andr?Majorel <URL:
http://www.teaser.fr/ ~amajorel/>
Respect for government [...] and its symbols is fundamentally fascist.
-- William Sommerwerck, on the subject of pissing on a national flag.