Snort mailing list archives

Re: Snort and APF firewall


From: Matt Kettler <mkettler () evi-inc com>
Date: Sat, 13 Dec 2003 15:02:31 -0500

At 07:11 PM 12/13/2003, Virgil Iancu wrote:
I need to know how I could activate alarms from portscan2 preproccesor into a log file suitable for APF firewall.

First, I've never heard of anyone refer to "APF firewall" prior to this message. Next time, try to at least include some more detail about what exactly you are talking about.

Doing a crude search, APF appears to be "advanced policy firewall", which is IPTables based.
http://www.rfxnetworks.com/apf.php


If it's just IPTables, use snortsam, or something of the like.

http://www.snortsam.net/


-------------------------------------------------------
This SF.net email is sponsored by: IBM Linux Tutorials.
Become an expert in LINUX or just sharpen your skills.  Sign up for IBM's
Free Linux Tutorials.  Learn everything from the bash shell to sys admin.
Click now! http://ads.osdn.com/?ad_id=1278&alloc_id=3371&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: