Linux Netfilter discussions
 help / color / mirror / Atom feed
* detect portscans in DNATed ports
@ 2002-10-10 12:33 Leonardo Rodrigues ( listas )
  2002-10-10 18:52 ` Hauke Lampe
  0 siblings, 1 reply; 2+ messages in thread
From: Leonardo Rodrigues ( listas ) @ 2002-10-10 12:33 UTC (permalink / raw)
  To: netfilter ML


    Hello Guys,

    I've a firewall script that deals with portscan in its external
interface. I'm doing that using psd module, which works just fine for this
situation. psd module is being called on INPUT rule.

    Altough it works absolutely fine when someone tries to portscan the
firewall, it seems to show all DNATed ports on the scanner. I'm sure it's
doing that because no DNATed packet reached INPUT rule, where psd is being
applied.

    Question is: in which chain/rule should I use psd module to get portscan
in DNATed ports ?? I was thinking in doing this on NAT OUTPUT .... what do
you think ?

    Sincerily,
    Leonardo Rodrigues



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2002-10-10 18:52 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-10-10 12:33 detect portscans in DNATed ports Leonardo Rodrigues ( listas )
2002-10-10 18:52 ` Hauke Lampe

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox