From: Jack Bowling <jbinpg@shaw.ca>
To: netfilter@lists.samba.org
Subject: Re: Question
Date: Fri, 21 Jun 2002 19:11:28 -0700 [thread overview]
Message-ID: <0GY3001U64R6B2@l-daemon> (raw)
In-Reply-To: <20020621231230.XKAD19225.mta07-svc.ntlworld.com@there>
** Reply to message from Antony Stone <Antony@Soft-Solutions.co.uk> on Sat, 22 Jun 2002 00:12:28 +0100
> On Friday 21 June 2002 7:31 pm, James Mello wrote:
>
> > > Also I'm wondering say if I have a dmz and allow people to come into a
> > > server on port 80, will netfilter inspect the packet on all 7 layers
> > > of the OSI model and make sure that it is actually a http packet and
> > > following the rules and protocol specifications of http?
> >
> > No, but there are experimental modules that will allow you to enforce
> > your own rules. I've heard of some IDS or attack detection capabilities
> > being done through IP tables.
>
> What sort of modules ? I *hope* you don't mean the 'string' match ?
>
> I'm not aware of anything based on IPtables which makes an effective (OSI
> layer 7) IDS - it's just not designed for it, being a packet filter.....
There is the psd module. Check it out.
jb
--
Jack Bowling
mailto: jbinpg@shaw.ca
next prev parent reply other threads:[~2002-06-22 2:11 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-06-21 17:33 Question Krish Ahya
2002-06-21 17:40 ` Question Antony Stone
2002-06-21 18:31 ` Question James Mello
2002-06-21 23:12 ` Question Antony Stone
2002-06-21 23:16 ` Question James Mello
2002-06-21 23:26 ` Question Antony Stone
2002-06-22 2:11 ` Jack Bowling [this message]
2002-06-22 15:25 ` Question Stephen Frost
2002-06-22 15:42 ` Question Ramin Alidousti
2002-06-21 18:59 ` Question Nick Drage
2002-06-21 19:41 ` Question Rowan Reid
2002-06-22 0:26 ` Question Sascha Reissner
-- strict thread matches above, loose matches on Subject: below --
2003-06-12 20:41 question Sander Sneekes
2003-06-12 22:11 question George Vieira
2003-09-25 14:04 question emiliano
2005-10-27 7:55 question Marcin Giedz
2005-10-27 8:18 ` question Ruprecht Helms
2005-10-27 8:39 ` question Marcin Giedz
2005-10-27 9:09 ` question Ruprecht Helms
2005-10-27 9:28 ` question Sorin Panca
2005-10-27 9:40 ` question Marcin Giedz
2005-10-27 10:04 ` question Oskar Andreasson
2005-10-27 10:25 ` question Marcin Giedz
2005-10-27 10:37 ` question Oskar Andreasson
2005-10-27 11:18 ` question Marcin Giedz
2005-10-27 13:28 ` question Oskar Andreasson
2006-06-21 12:14 question Fabio S. Silva
2006-06-21 12:23 ` question Sietse van Zanen
2008-04-28 9:01 Question Karim Reda Fakhir
2008-04-28 10:11 ` Question Jan Engelhardt
2008-04-29 1:51 ` Question Diego Lacerda
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=0GY3001U64R6B2@l-daemon \
--to=jbinpg@shaw.ca \
--cc=netfilter@lists.samba.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox