On 2011-03-02 21:51, Richard Brendörfer wrote:
> Hi,
> this is the first time when I write on mailing list.
> If this subject was discussed in the past please don't shoot me, just trow
> me a bone.
> 
> I was wonder if pf can detect packets that match a signature/fingerprint of
> a virus, like it makes with the OS fingerprints.
> 
> Let's assume that I start to download eicar then pf 'see' the signature of
> the pachet(s) and drop the connection.
> Is this possible ?
> 

Not direct with pf, but in combination with snort and sortsam.
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-pf
To unsubscribe, send any mail to "[email protected]"

Reply via email to