Snort mailing list archives

RE: Blocking individual IP's


From: Omolayo Salako <OSalako () corp goamerica net>
Date: Thu, 11 Apr 2002 10:14:22 -0400

i think ISS does that, alternatively you can just block it at your edge
router

-----Original Message-----
From: O'Brien, James [mailto:JOBrien () Hunter COM]
Sent: Thursday, April 11, 2002 8:53 AM
To: 'snort-users () lists sourceforge net'
Subject: [Snort-users] Blocking individual IP's


Hello all.

What options are there (rules or otherwise) to block individual IP's from
malicious/annoying public IP's?  I'm sick of seeing numerous attempts from
the same couple of dozen addresses and want to squelch them once and
for-all.  We run checkpoint, and the snortsam plugin to block scans, and
I've messed with custom snort rules to block ip's that have continously
bothered me, but it is an in-elegent solution at best.  Has anyone out there
come up with a better way to do this using snort or some other IDS that will
talk to Checkpoint's firewall 1??

Thanks for your time,

Jim O'Brien
Systems Admin

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: