Re: something like bruteblock for pf?

2009-08-23 Thread Balázs Mátéffy
Hi guys, I'm using bruteforceblocker at the moment on my systems, thanks for this great utility Daniel! Can you tweak it to be able to get the ips from proftpd or any other log, or its working out of the box, you just have to set it up in syslog.conf(didn't see that feature in the doc.)? Or for

Re: something like bruteblock for pf?

2009-08-23 Thread Daniel Gerzo
Len Conrad wrote: I've used bruteblock, which manages ipfw, for blocking SMTP attackers and reducing smtp connects by 10s of 1000s per day. Anybody know of anything similar for pf? security/bruteforceblocker -- S pozdravom / Best regards Daniel Gerzo, FreeBSD committer ___

Re: something like bruteblock for pf?

2009-08-23 Thread Nickola Kolev
On Sun, 23 Aug 2009 18:21:16 +0300 Artyom Viklenko wrote: > Len Conrad wrote: > > I've used bruteblock, which manages ipfw, for blocking SMTP > > attackers and reducing smtp connects by 10s of 1000s per day. > > > > But bruteblock, which hasn't moved in 3 years, logged a lot of > > errors like

Re: something like bruteblock for pf?

2009-08-23 Thread Artyom Viklenko
Len Conrad wrote: I've used bruteblock, which manages ipfw, for blocking SMTP attackers and reducing smtp connects by 10s of 1000s per day. But bruteblock, which hasn't moved in 3 years, logged a lot of errors like "failed to ..." which didn't seem to bother its effectiveness, but was concer

Re: something like bruteblock for pf?

2009-08-23 Thread Len Conrad
>n 08/22/2009 10:57 PM Peter Maxwell wrote: >>2009/8/23 Len Conrad : >>>I'm looking for something like bruteblock that logwatches (smtp, ssh, ftp, >>>whatever) and inserts/removes TCP block rules into pf for x hours, so the >>>protocol daemons are involved. >... >>Before implementing something l

Re: something like bruteblock for pf?

2009-08-23 Thread Ron Wilhoite
On 08/22/2009 10:57 PM Peter Maxwell wrote: 2009/8/23 Len Conrad : I'm looking for something like bruteblock that logwatches (smtp, ssh, ftp, whatever) and inserts/removes TCP block rules into pf for x hours, so the protocol daemons are involved. ... Before implementing something like this,

CARP failover strange behaviour-two master states on master and backup server

2009-08-23 Thread Arlen Drina
Hi list, I am using PF + CARP on OpenBSD 4.5 for my redundant firewall, but I have some strange situations, I cannot understand very well. So please review and give me your opinion, firewalls perform redundancy as expected and works but some stuff are not clear 1 ) master configuration for carp i