Hi there, continuing on this thread....
That's a implementation I was wondering to do, but interacting with SNORT, to make changes in the destination address (squid or iptables routing). If an attack were detected, it would redirect the traffick to another server or some king of honneypot. Anybody know if it's OK? Is it too hard to do? Thanks Alisson Leite de Morais Veras Sao Paulo - Brazil