From owner-freebsd-isp Tue Jan 14 1: 3:47 2003 Delivered-To: freebsd-isp@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id F261D37B401 for ; Tue, 14 Jan 2003 01:03:46 -0800 (PST) Received: from saturn.mics.co.za (saturn.mics.co.za [196.34.165.130]) by mx1.FreeBSD.org (Postfix) with ESMTP id 6F99843ED8 for ; Tue, 14 Jan 2003 01:03:45 -0800 (PST) (envelope-from mark@mics.co.za) Received: from root by saturn.mics.co.za with scanned_ok (Exim 3.36 #1) id 18YMjw-0006FO-00 for freebsd-isp@freebsd.org; Tue, 14 Jan 2003 10:48:08 +0200 Received: from opium.co.za ([196.34.165.210]) by saturn.mics.co.za with esmtp (Exim 3.36 #1) id 18YMjv-0006FH-00 for freebsd-isp@freebsd.org; Tue, 14 Jan 2003 10:48:07 +0200 Date: Tue, 14 Jan 2003 11:03:40 +0200 (SAST) From: Mark Bojara X-X-Sender: mark@opium.co.za To: freebsd-isp@freebsd.org Subject: snort with ipfw Message-ID: <20030114110205.S291-100000@opium.co.za> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII X-Virus-Scanned: MICS Online Virus Scanner (virusalert@mics.co.za) Sender: owner-freebsd-isp@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Hello, Is it possible set up snort so that when it detects a portscan it automatically adds a ipfw rule and blocks that ip address? Regards Mark Bojara ---------------------------------------------------------------- NEWS! Survivor of siamese twins joins parents ---------------------------------------------------------------- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-isp" in the body of the message