From mboxrd@z Thu Jan 1 00:00:00 1970 From: Alejandro Flores Subject: Re: learning firewall Date: Thu, 02 Sep 2004 19:01:43 -0300 Sender: netfilter-bounces@lists.netfilter.org Message-ID: <1094162502.11169.2.camel@aflores> References: <20040902191645.GA28800@omega.lacnic.net.uy> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <20040902191645.GA28800@omega.lacnic.net.uy> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii" To: Pablo Allietti Cc: netfilter@lists.netfilter.org Hello Pablo, Take a look at the contrib folder in snort sources, there's a program called Guardian. It read alerts generated by snort and add a dynamic rule to iptables to block the source. Another one is SnortSam, which can block in iptables, checkpoint, pix, etc.. etc... Regards, Alejandro Flores > hi all i have a question. > > exist any soft based in iptables to have the option LEARN ?? > > example > > i run snort in my system when detect a intrusion add the ip address to > the iptables table. > > exist this ?? -- -- Alejandro Flores http://www.triforsec.com.br/ http://www.defenselayer.com/ http://www.nabucodonosor.org/