OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Seth Arnold (sarnoldwirex.com)
Date: Thu May 02 2002 - 12:48:03 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Thu, May 02, 2002 at 08:41:23AM -0600, Joe McCray wrote:
    > Can I do the limiting of outbound connections with the
    > notification via email to me with IPchains & Firewall features,
    > and basic scripting within Linux? Basically, can I do it on
    > something that is free, and not Checkpoint or Cisco?

    I believe the IPChains or IPTables linux firewalls offer a LOG
    functionality, that will send messages to syslog. You can use a log
    watcher tool to search for those messages and send you email when
    something odd happens. Firewalls typically try to be as simple as
    possible, especially since they run in kernel code, so sending emails
    directly from the firewall is .. not likely to happen, and I'd be
    cautious of anything that did send email from the kernel.

    Look around for swatch, logwatch, and the IPChains or IPTables HOWTOs.

    Cheers :)

    -- 
    http://sardonix.org/
    

    -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see http://www.gnupg.org

    iD8DBQE80XvS1XMg6PgdEDQRAoEGAKC52RFTRlaznlgzq34TOjUlbdV2hACglyuJ y9R3F+4yvLVAiJkRPDv/fHI= =sjER -----END PGP SIGNATURE-----