Hi Aba3k, I wrote a paper about ossec + snort sometime ago and I think it could help you
http://www.dynsec.com.br/arquivos/ossec-snort-activeresponse_english.pdf Regards, Rodrigo Montoro(Sp0oKeR) On Fri, Oct 24, 2008 at 8:59 PM, aba3k <[EMAIL PROTECTED]> wrote: > > It's possible? I'm using snort + ossec, but i don't want to block my > network, then they in the whitelist. But i want to block unauthorized > access (caught by snort) to the internet. > -- =========================== Rodrigo Montoro (Sp0oKeR) Intrusion Detection Analyst SnortCP / RHCE / LPIC-I / MCSO http://www.spooker.com.br http://www.snort.org.br http://www.linkedin.com/in/spooker ===========================
