Re: virus scanning with iptables

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Khanh Tran wrote:
How about port scanning clients behind from the firewall?  Suggestions?
I'm thinking of something that could be scripted to append an iptables
rule to block the MAC address of the offending client, then notify me.
Am I looking at an NMAP plugin possibly?


You would probably want to have something like SNORT tied into iptables. Have something like SNORT look for certain alerts and then when it finds them it sends a 'signal' to a daemon on the firewall that inserts a DROP rule for that IP address in a 'dynamic chain'.


--
Stephen John Smoogen	        | CCN-5 Security Team
LANL SIRT Team Leader           | SMTP:  smoogen@xxxxxxxx
Los Alamos National Laboratory  | Voice: 505.664.0645
Ta-03 SM-1498 MS: B255 DP 10S   | FAX:   505.665.7793
Los Alamos, NM 87545            |


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux