I would be very interested in a script/setup like this, so I second the suggestion of posting it somewhere.

On a minor off topic question, has anyone gotten the linux-pam/pam_tally to work in 5.x?

Due to security requirements at work I need either that or something similar.

At 05:28 PM 4/7/2005, Jon Adams wrote:


Marian Hettwer wrote:

On Mi, 6.04.2005, 17:57, Willem Jan Withagen sagte:


I've build some swatch-rules that after two of these hits, I dump
the host into ifpw-deny space.


Aye. I thought about writing a script, doing the same like yours, too.
Could you post this script somewhere, so that I could add some
functionality or just use it ?


This is similar to what I do... except

I just run a cronjob every so often... daily.. weekly.. what have you.. that will restart ipfw... probably there is a cleaner solution, but it
does the job for me.... as far as cleaning out the dozens of IPs that get blocked for connecting to ports they shouldnt on my boxes


_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "[EMAIL PROTECTED]"

Reply via email to