This is a discussion on Re: [Snort-users] Block within the Snort forums, part of the System Security and Security Related category; --=-vipCi7RJ5fF++x5LncLE Content-Type: text/plain Content-Transfer-Encoding: quoted-printable On Mon, 2004-02-16 at 12:48, Matt ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
--=-vipCi7RJ5fF++x5LncLE Content-Type: text/plain Content-Transfer-Encoding: quoted-printable On Mon, 2004-02-16 at 12:48, Matt Kettler wrote: > 3) snortsam > - supports a wide variety of firewalls, but acts slightly after=20 > the fact. This means the packet that contained the trigger gets passed, b= ut=20 > subsequent packets will get blocked, limiting the impact of the exposure. While that is true, it can block on more than one enforcement point at the same time. Plus it can create a semi-permanent (full block on IP for a defined time interval) block or isolate systems. While not real time, it has a lot of flexibility going for it. Cheers, Frank (Sorry, haven't pitched Snortsam in a while ;) --=20 Warning at the Gates of Bill: =20 Abandon hope, all ye who press <ENTER> here... --=-vipCi7RJ5fF++x5LncLE Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (FreeBSD) iD8DBQBAMUkvJjGc5ftAw8wRAuSNAJ9F31MGwqw9ZecIpyTq19 dQJma7EQCcDazB wsoqcuJA1TLrpA0ARs7fhE0= =8Hje -----END PGP SIGNATURE----- --=-vipCi7RJ5fF++x5LncLE-- ------------------------------------------------------- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps & Web services for Linux with a free DVD software kit from IBM. Click Now! http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |