Snort mailing list archives

firewall rules modification based on snort logs


From: Gaurav Kumar <gaurav_e2 () yahoo com>
Date: Tue, 10 Jun 2003 02:21:15 -0700 (PDT)

hello snort user...
i was wondering if some script or tool is avaliable to modify the firewall rules based on snort logs (i am using mysql 
database for snort logging).
for example is someone is ping flooding my server, tool will read the logs from snort and modify the iptable rule to 
DENY the ip address to access my server.
 


Gauarv Kumar
 
Security Analyst
E-mail - gaurav () e2-labs com
Phone - +91-40-23555942, 23556538 
Mobile- +91-40-31068650
e2 labs
India
 
[This e-mail may contain confidential and/or privileged information. If you are not the intended recipient (or have 
received this e-mail in error) please notify the sender immediately and destroy this e-mail. Any unauthorized copying, 
disclosure or distribution of the material in this e-mail is strictly forbidden.]



---------------------------------
Do you Yahoo!?
Free online calendar with sync to Outlook(TM).

Current thread: