Giacomo Fazio a écrit :
It is a perl script....how can i use under Secure Platform?

you can install a perl rpm on your secureplatform.
depending on the ng/ngx release, you have to take the correct rpm.
depending also on what this script requires, you'll also need to get some modules.
Thanks
Giacomo
----- Original Message ----- From: "Roger P Herr" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Thursday, May 03, 2007 3:09 PM
Subject: Re: [FW-1] R55 Blocking connection


there is a script called scanalert.pl that you can use as a user defined alert, assign that to the Smart Defense, or build your own rule that catches the connections and use the user defined alert.

Roger Herr

WhyNot? Consulting Services
24165 IH 10 West Suite 217-183
San Antonio, Texas 78257
210-860-3990
Some men see things as they are and say why?
I dream things that never were and say "Why Not?"
                                               -Robert F. Kennedy

Or the original

You see things; and you say "Why?" But I dream things that never were; and I say "Why not?"
George Bernard Shaw
(1856-1950)
----- Original Message ----- From: "Giacomo Fazio" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Thursday, May 03, 2007 8:43 AM
Subject: Re: [FW-1] R55 Blocking connection


Thanks.

But how cai i say to fw1 to block connection only if the smart defense tell me
Successive Multiple Connection are reached?

Giacomo
----- Original Message ----- From: "Roger P Herr" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Thursday, May 03, 2007 2:22 PM
Subject: Re: [FW-1] R55 Blocking connection


fw sam -t <time in seconds> -i subsrv <src ip> <netmask> <dst ip> <netmask> <service> <protocol>
like

fw sam -t 3600 -i subsrv 192.168.1.1 255.255.255.255 172.16.1.0 255.255.255.0 22 tcp


Roger Herr

WhyNot? Consulting Services
24165 IH 10 West Suite 217-183
San Antonio, Texas 78257
210-860-3990
Some men see things as they are and say why?
I dream things that never were and say "Why Not?"
                                               -Robert F. Kennedy

Or the original

You see things; and you say "Why?" But I dream things that never were; and I say "Why not?"
George Bernard Shaw
(1856-1950)
----- Original Message ----- From: "Giacomo Fazio" <[EMAIL PROTECTED]>
To: <[email protected]>
Sent: Thursday, May 03, 2007 7:23 AM
Subject: [FW-1] R55 Blocking connection


Hello,

i have fw1 R55.

How can i block for a specified time a source address that is doing a lot of, for example, ssh connection
to my network?

Thanks
Giacomo
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================


=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================


=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================


=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to