On 7/6/06, Bharj, Gagan <[EMAIL PROTECTED]> wrote:
Hello Folks,
Our server is getting hammered on a daily basis by IPs trying to open an ssh
session. Currently, I'm manually putting the subnets (in a pf table) that are
repeatedly trying to get in. As you can see, this list will eventually get
very big and will be unmaintainable. Is there any way that I can say only
allow IP addresses from particular ISPs or domains?
Please see if this will help you
http://freshmeat.net/projects/snort2pf/
Kind Regards
Siju