Holger Burde
2002-11-30 17:45:35 UTC
Hi;
I found that iptables has (via patch-o-matic) a option to build a Portscan detection Module (psd) which blocks scanning hosts (nmap etc.) for some time and efficiently makes auto-scanning sort of impossible.
Is this also possible with OpenBSD pf or is it planed to add this feature ? (from man faq google etc. it seems not)
PS The Watchguard Firewalls also have such a feature which is turned on by default.
PS2 I want this on a firewall so using some IDS does not work since the packets are dropped before the
IDS would see them ...
hb
I found that iptables has (via patch-o-matic) a option to build a Portscan detection Module (psd) which blocks scanning hosts (nmap etc.) for some time and efficiently makes auto-scanning sort of impossible.
Is this also possible with OpenBSD pf or is it planed to add this feature ? (from man faq google etc. it seems not)
PS The Watchguard Firewalls also have such a feature which is turned on by default.
PS2 I want this on a firewall so using some IDS does not work since the packets are dropped before the
IDS would see them ...
hb