Hi, better way would be to use apache2 , mod_clamd, and squid / frox or use dansgurdian, or some comercial Produkt This would do the job for http/ftp...clamd also works with amavis-new for antispam and antivirus to smtp. Regards Stephen J Smoogen schrieb:
I was looking at a more general solution for scans and non webbased worms. The largest traffic I see dropped is 135:139, 445 traffic. Getting those boxes off the network as quickly as possible is a big win.
For email based viruses I have been using a combo of clamd/mimedefang on some sites. The larger site is using some other method.
Khanh Tran wrote:
How about port scanning clients behind from the firewall? Suggestions? I'm thinking of something that could be scripted to append an iptables rule to block the MAC address of the offending client, then notify me. Am I looking at an NMAP plugin possibly?
You would probably want to have something like SNORT tied into iptables. Have something like SNORT look for certain alerts and then when it finds them it sends a 'signal' to a daemon on the firewall that inserts a DROP rule for that IP address in a 'dynamic chain'.
-- Stephen John Smoogen | CCN-5 Security Team LANL SIRT Team Leader | SMTP: smoogen@xxxxxxxx Los Alamos National Laboratory | Voice: 505.664.0645 Ta-03 SM-1498 MS: B255 DP 10S | FAX: 505.665.7793 Los Alamos, NM 87545 |