September 2007
Intermediate to advanced
336 pages
9h 7m
English
In this section, we'll dive into a few juicy examples of using psad in active response mode, and we'll show how it detects and blocks an IP address that is consistently scanning a Linux system that has iptables facilities enabled. See the standard network diagram in Figure 8-1 for all active response examples in this section. As usual, the default iptables policy implemented by the iptablesfw script from "Default iptables Policy" on page 20 is implemented on the firewall.

Figure 8-1. Default network diagram
Given the highly configurable nature of psad, the active response examples in this ...
Read now
Unlock full access