Snort mailing list archives

Re: snort + libradiate + inline?


From: Erek Adams <erek () snort org>
Date: Wed, 17 Sep 2003 08:43:17 -0400 (EDT)

On Mon, 15 Sep 2003, jon baer wrote:

has anyone seen anything like the such where something could be done for
deassociating + blocking clients off a wireless lan?

id think in a chain ur write something like (just an idea):

-A INPUT -s 192.168.0.10 -j DEASSOCIATE

im guessing in snort you'd fit it into the flex-resp/inline response:

drop tcp 192.168.0.10 any -> any any (resp: deassociate;)

im just looking to see if there are other doing anything likewise in terms
of active wireless response.

Wlan + OpenBSD + AuthPF == Solution

Check it out, you'll be impressed.  I know I was!

-----
Erek Adams

   "When things get weird, the weird turn pro."   H.S. Thompson


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: