Snort mailing list archives
Re: fbidsmate and watchguard firebox
From: Matt Kettler <mkettler () EVI-INC COM>
Date: Thu, 04 Sep 2003 17:24:13 -0400
At 04:08 PM 9/4/2003 -0400, Hamilton, Robert wrote:
Any way to directly call fbidsmate from snort alert rules?
Directly from snort there is no way to call *any* firewall tool.Fundamentally out of the box snort is an IDS and only an IDS. It has no support for reconfiguring any firewalls of any sort. No support for IpTables, IPF, cisco, watchguard, or any other kind of firewall is present.
It does have a *very* limited ability to attempt to kill offensive connections using flexresp, but this doesn't reconfigure a firewall.. "react:block" just causes flexresp to generate some tcp reset packets or icmp unreachable messages. It is however not reliable when racing against an educated attacker (If the attacker knows flexresp is going to issue a reset in response to an attack, they can attempt to advance the sequence number before flexresp can respond. Flexresp is being improved to help avoid this, but it still fundamentally boils down to a race where flexresp has the speed advantage, but the attacker has the advantage of knowing when the race will start and can be prepared in advance. .)
It's only add-ons such as snortsam which extend firewall modification capability, bringing snort more into the realm of IPS type functionality than IDS functionality.
And really, this separation into different add-on tools allows snort to be as flexible as possible without becoming insanely bloated. Snort by itself focuses on being a good IDS, and projects like snortsam and inline-snort focus on firewall manipulation.
------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- fbidsmate and watchguard firebox Hamilton, Robert (Sep 04)
- Re: fbidsmate and watchguard firebox Matt Kettler (Sep 04)
- Re: fbidsmate and watchguard firebox Jeff Nathan (Sep 04)
- Re: fbidsmate and watchguard firebox Jeff Nathan (Sep 04)
- Re: fbidsmate and watchguard firebox Matt Kettler (Sep 05)
- Re: fbidsmate and watchguard firebox Jeff Nathan (Sep 07)
- Re: fbidsmate and watchguard firebox Jeff Nathan (Sep 04)
- Re: fbidsmate and watchguard firebox Matt Kettler (Sep 04)
- <Possible follow-ups>
- RE: fbidsmate and watchguard firebox Hamilton, Robert (Sep 05)