OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: John Girvin (john.girvinOSARIUS.COM)
Date: Thu Apr 12 2001 - 03:04:05 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    > snort does not do anything like he was asking. snort is a very good basic
    > ids.
    FWIW, the latest 1.7 "FlexRESP" (Flexible RESPonse) release of
    Snort can send tcp resets or icmp unreachable packets back in
    response to packets that match any of its rules.

    Or at least thats what the docs say; theres problems with this
    code on 2K Advanced Server and I cant get it to work (yet?)

    > windows 2000 offers some sembelance of what you are looking for.
    > look into the IP security policy for your machine. The rulesets
    > allowed can be pretty much as complex as you need in a simple packet
    > filtering situation.
    OK thanks I'll check that out. I thought that stuff was about
    IPSec / VPNs etc...

    One extra question now ... on NT4 theres a checkbox to enable/disable
    IP forwarding between interfaces on a multihomed box ... where's that
    gone in 2K? I know its /supposed/ to be off by default, but we're a
    paranoid bunch and I'd like to check and be sure :)

    Cheers,
    /John