From owner-freebsd-security Mon May 22 14:45:43 2000 Delivered-To: freebsd-security@freebsd.org Received: from spike.brainlink.com (spike.brainlink.com [206.127.59.100]) by hub.freebsd.org (Postfix) with ESMTP id 4FB1637B5AE for ; Mon, 22 May 2000 14:45:32 -0700 (PDT) (envelope-from spork@spike.brainlink.com) Received: (from spork@localhost) by spike.brainlink.com (8.9.3/8.9.3) id RAA03230; Mon, 22 May 2000 17:44:01 -0400 (EDT) (envelope-from spork) Date: Mon, 22 May 2000 17:44:00 -0400 From: Spike Gronim To: Blake Matheny Cc: freebsd-security@freebsd.org Subject: Re: Firewall Rules Message-ID: <20000522174400.A3178@spike.brainlink.com> Reply-To: gronimw@stuy.edu References: <20000522110814.A5867@toaster.sun4c.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Mailer: Mutt 1.0.1i In-Reply-To: ; from matheny@bussert.com on Mon, May 22, 2000 at 01:44:46PM -0500 X-PGP-Public-Key: http://www.gronim.com/spike/pubkey.asc X-PGP-fingerprint: 05 92 88 05 3C DB F2 40 AB 1D AE 2A F0 E5 FA A5 X-Geek-Code: http://www.gronim.com/spike/geekcode Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org On Mon, May 22, 2000 at 01:44:46PM -0500, Blake Matheny wrote: > I'm thinking of writing something that utilizes something like arpwatch to > keep an eye on mac/ip address mappings. Then if a mac address changes ip > it get's added to a list which is filtered by ipfw. Does anyone know of > something like this or have any other suggestions? One problem I see with that is that I could maliciously change my IP to that of another machine and get it blocked from the net. > > Blake Matheny > Bussert Consulting > Network Engineer > (765)423-2100 > matheny@bussert.com > > > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-security" in the body of the message -- --Spike Gronim gronimw@stuy.edu "Oh yes? An obscene triangle which, has more courage than the word." To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message