On Thu, 28 Dec 2000, Michael O'Henly wrote:

>The way I understand it, portsentry senses a port scan and then immediately
>creates a rule that adds the scanning host to a REJECT or DENY rule. So if
>you've told your firewall to do this by default for all external hosts, is
>that the same thing?

It is for the major part. But portsentry also adds a line in the messages
logfile, where I can see what IP has tried to do something. If one is
getting too boring, I smoke the person out and report him to his ISP.

Paul

-- 
Disclaimer: "These opinions are my own,
though for a small fee they can be yours too."

http://nlpagan.net - ICQ 147208 - Registered Linux User 174403
             Linux Mandrake 7.2 - Pine 4.31


Reply via email to