[SGVLUG] security tools

James Neff jneff at tethyshealth.com
Tue Dec 4 07:12:17 PST 2007


Greetings,

Has anyone used any of the tools from http://www.cipherdyne.org/  like 
psad, fwknop, or fwsnort?

I'm looking for an easy way to report logs from Iptables because I'm too 
lazy to build my own log parser.  But one thing I liked in the FAQ of 
psad is this:

http://www.cipherdyne.org/psad/docs/faq.html#auto_block

Looks like it has the ability to automatically block an IP address based 
on a a certain threshold of traffic.
Let me know if anyone has used this or have something else you recommend.

Thanks,
James


More information about the SGVLUG mailing list