Re: pf idea

2004-08-29 Thread Damien Miller
Christopher Keeley wrote: > Dear All > > I have an idea which I would like to run by developers and users alike. > Does anyone think 'pattern matching' on packets values would be > a useful addition to pf' current capabilities? > > The idea would be to allow users to write simple numeric sequen

Re: pf idea

2004-08-29 Thread Greg Hennessy
On 29 Aug 2004 08:01:40 -0700, [EMAIL PROTECTED] (Christopher Keeley) wrote: >Does anyone think 'pattern matching' on packets values would be >a useful addition to pf' current capabilities? As with the equivalent on iptables its a crap idea. Using tools such as snortsam one generate rules to d

Re: pf idea

2004-08-29 Thread Jason Dixon
On Aug 28, 2004, at 12:08 PM, Christopher Keeley wrote: I have an idea which I would like to run by developers and users alike. Does anyone think 'pattern matching' on packets values would be a useful addition to pf' current capabilities? A simple search of the list archives reveals this has been r

Re: pf idea

2004-08-29 Thread Ken Simpson
Sort of like a kernel-layer snort? That would be cool. Christopher Keeley [28/08/04 17:08 +0100]: > Dear All > > I have an idea which I would like to run by developers and users alike. > > Does anyone think 'pattern matching' on packets values would be > a useful addition to pf' current capabil

pf idea

2004-08-29 Thread Christopher Keeley
Dear All I have an idea which I would like to run by developers and users alike. Does anyone think 'pattern matching' on packets values would be a useful addition to pf' current capabilities? The idea would be to allow users to write simple numeric sequences representing packet values into the