Hi,
better way would be to use apache2 , mod_clamd, and squid / frox
or use dansgurdian, or some comercial Produkt
This would do the job for http/ftp...clamd also works with amavis-new
for antispam and antivirus to smtp.
Regards
Stephen J Smoogen schrieb:
Khanh Tran wrote:
How about port scanning clients behind from the firewall? Suggestions?
I'm thinking of something that could be scripted to append an iptables
rule to block the MAC address of the offending client, then notify me.
Am I looking at an NMAP plugin possibly?
You would probably want to have something like SNORT tied into iptables.
Have something like SNORT look for certain alerts and then when it
finds them it sends a 'signal' to a daemon on the firewall that inserts
a DROP rule for that IP address in a 'dynamic chain'.