Linux Netfilter discussions
 help / color / mirror / Atom feed
* UDP Scan detection with xtables-addon psd
@ 2011-08-11 10:16 andreas
  2011-08-11 13:54 ` Jan Engelhardt
  0 siblings, 1 reply; 4+ messages in thread
From: andreas @ 2011-08-11 10:16 UTC (permalink / raw)
  To: netfilter

Hi,

i'm working on a dynamic firewall and one sensor should be the portscan.
I want to detect port scans and forward them to the target that handles
the sensors and the blocking. So i saw that xtables-addons support
portscan with psd and lscan. As i want to scan also UDP scans i choose
psd instead of lscan.
But i can't get psd to detect nmap UDP scans. I played around with the
four values of psd but i never got the UDP scans logged. The TCP scans
are logged, at least nmap -sT, -sS, -sF, -sX, -sN are logged, -sA is
missing and so is the UDP scan with -sU.
I did not use any special nmap parameters except -P0. The machine is a
gentoo system with 2.6.38 Kernel, xtables addons 1.37 and iptables 1.4.11.1.

Does anyone know how psd can detect UDP scans? Did i miss anything?

And another question is, is the psd development stopped and do you
suggest to use lscan or do you have any other suggestion for me?

If not i guess i have to write my own modul or patch psd/lscan to get
the missing scans detected.

thanks so far and greetings from Germany,

Andi

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2011-08-11 16:10 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-08-11 10:16 UDP Scan detection with xtables-addon psd andreas
2011-08-11 13:54 ` Jan Engelhardt
2011-08-11 14:32   ` andreas
2011-08-11 16:10     ` Jan Engelhardt

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox