Re: active firewall

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tuesday 23 Sep 2003 2:26 pm, Nik Trevallyn-Jones wrote:

> 1  two new targets: ENLIST, DELIST
> These targets effectively cause one or more new rules to be automatically
> added/removed to/from the firewall in response to matching the associated
> rule. This allows the firewall to respond to certain events by
> adding/deleting rules within itself.
You can do most of what you are after with the 'RECENT' match and target ...

I.e. if 'X' seen from 'Y' within n seconds - block Y 
You can create some quite interesting rulesets with recent and a few logic
chains .....

Mark
- -- 
Mark Vevers.    mark@xxxxxxx / mvevers@xxxxxx
Principal Internet Engineer, Internet for Learning,
Research Machines Plc  AS 5503
Tel: +44 1235 854314,   Fax: +44 1235 854693
- --
GPG Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xB08F3CA3
Fingerprint: 85BA 30C4 9EC8 1792 4C8C   C31E 58B5 3D1C B08F 3CA3
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE/cGKVWLU9HLCPPKMRAs7pAJ94G/Tra46YJhANHjxcax+xFFeYHACfbpf5
ETRkADtzBYezwEUZq/qNzHg=
=mNJy
-----END PGP SIGNATURE-----




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux