Re: Snort as fail2ban

Ian Bowers via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CAOtTuaqeLUO7=K3Dtes7chYUdG-5UABVooViqgvY2RGG+7wUtQ@mail.gmail.com>
In pfsense, you can specify max new connections per second for a given
source host. If it exceeds that the source IP is banned for an hour. It's
not 24 hours, but it should functionally kill brute force attacks.

If you specifically want to use snort, you'd write a rule to match the
traffic you're interested in and run your Snort instance in blocking mode.
In your case you'd use something like "track by_src, count 5, seconds 300"
in the detection filter to specify 5 attempts in 5 minutes for example.

-Ian

On Thu, Jan 13, 2022 at 1:15 PM Evgeny via Snort-users <
[email protected]> wrote:

> Sorry, is it possible to configure Snort as fail2ban to block an IP after
> 5 attempts and block it for 24 hours?
> There is pfSense gateway with admin web interface and VPN.
> Could Snort protect pfSense web interface as fail2ban from-brute force
> attacks?
> Could Snort protect VPN (OpenVPN or L2TP/IPsec) connections on pfsense
> from brute-force attacks?
>
> --
> Best regards!
> _______________________________________________
> Snort-users mailing list
> [email protected]
> Go to this URL to change user options or unsubscribe:
> https://lists.snort.org/mailman/listinfo/snort-users
>
>         To unsubscribe, send an email to:
>         [email protected]
>
> Please visit http://blog.snort.org to stay current on all the latest
> Snort news!
>
> Please follow these rules:
> https://snort.org/faq/what-is-the-mailing-list-etiquette
>

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.