From owner-freebsd-questions@FreeBSD.ORG Thu Oct 6 18:04:35 2005 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C2F6916A431 for ; Thu, 6 Oct 2005 18:04:35 +0000 (GMT) (envelope-from fbsdlists@gmail.com) Received: from xproxy.gmail.com (xproxy.gmail.com [66.249.82.207]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5BF3343D45 for ; Thu, 6 Oct 2005 18:04:35 +0000 (GMT) (envelope-from fbsdlists@gmail.com) Received: by xproxy.gmail.com with SMTP id t15so322419wxc for ; Thu, 06 Oct 2005 11:04:34 -0700 (PDT) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=pNLHY/DmCZnRrdviP8RIC/y0Wz50Vr2+jAqgvxGgFYn0VBdprrmU9z3q/XUuJa+oihe+Gp/G4t1OrK9nHpRC4edBeQV86rce0UNPd6SQJxaNV5YPCLp0Uy2oGl6htbLUKc+sJZ9DVUpJloWu+ubU0w85nlS57nzIU1ySAJroYhc= Received: by 10.70.90.1 with SMTP id n1mr1512829wxb; Thu, 06 Oct 2005 11:04:34 -0700 (PDT) Received: by 10.70.67.15 with HTTP; Thu, 6 Oct 2005 11:04:34 -0700 (PDT) Message-ID: <54db43990510061104j11261ac4yb99ca7c742e0e4f2@mail.gmail.com> Date: Thu, 6 Oct 2005 14:04:34 -0400 From: Bob Johnson To: jmulkerin In-Reply-To: <4343D5CE.4040908@comcast.net> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline References: <54db439905092908455157e6a3@mail.gmail.com> <20051005085848.GA807@Alex.lan> <4343D5CE.4040908@comcast.net> Cc: bobo1009@mailtest2.eng.ufl.edu, freebsd-questions@freebsd.org Subject: Re: IPFW logging and dynamic rules X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Bob Johnson List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 06 Oct 2005 18:04:36 -0000 On 10/5/05, jmulkerin wrote: > How about using snort and guardian. Guardian.pl will add a ipfw rule > each time it sees an alert from Snort. You'll need to adjust the snort > rules for what you want to alert on but its a pretty safe and > lightweight asset. (just my novice 2 cents...) > Thanks, I'll look at Guardian. I had not planned to get that sophisticated about it, but even if I don't use it on this system, I have others where it may be just what I need. - Bob