LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-15-2007, 11:14 PM   #1
gizza23
Member
 
Registered: Jun 2005
Location: Chicago, IL, USA
Distribution: Fedora Core, CentOS
Posts: 188

Rep: Reputation: 31
Does IPCop act on Suspicious Activity


Hi All,

I wanted to know if IPCop did anything other than log suspicious activity when detected. In particular, I would like to know if IPCop would block the activity if triggered to do so. Thank you!

Gregori J.
 
Old 08-16-2007, 04:24 AM   #2
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Rep: Reputation: 31
Arrow

I have no idea whether snort in Ipcop is a IDS or IPS.

As far as i know, endian firewall provides the interface for oyu to download the rules from snort official website based on the permission/packages you register.

I don't know whether Ipcop allow you do the above task. If you know, please let me know.


I hope this help.
 
Old 08-16-2007, 07:12 AM   #3
gizza23
Member
 
Registered: Jun 2005
Location: Chicago, IL, USA
Distribution: Fedora Core, CentOS
Posts: 188

Original Poster
Rep: Reputation: 31
Thank you!
So does anyone actually know f IPCop fileters based on Snort rules?
 
Old 08-17-2007, 12:56 AM   #4
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Rep: Reputation: 31
Please help gizza123. He in trouble.

Thanks for your help.
 
Old 08-19-2007, 02:53 PM   #5
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
I do not believe IPCop has IPS capability out-of-the-box. I do not know the latest capabilities of IPCop (I ran it maybe a year ago, doing a bake-off between IPCop, Smoothwall, and ClarkConnect), but I don't believe it has the capability you speak of.

Perusing the IPCop site and reading the FAQ and docs, I didn't see any mention of autoblocking capability. When I was using it, I had to manually block any questionable activity I observed. The other two gateway OSs I used were the same way.

I'd check the ruleset to be sure. The rules should hint at what is done with malicious activity (as an IPS, Snort blocks based on what is indicated in the rules).
 
Old 08-21-2007, 07:51 AM   #6
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Rep: Reputation: 31
Does we need to edit the default rules of IpTables and snort rules ?

Thanks for your help.
 
Old 08-21-2007, 06:27 PM   #7
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
Quote:
Originally Posted by Peter_APIIT View Post
Does we need to edit the default rules of IpTables and snort rules ?

Thanks for your help.
I believe it requires more than just editing the default rules of Snort and IPTables. I believe you also need to utilize Snort-inline, which, from my understanding, turns your gateway device into more of a router (with the capability of blocking)...dunno if that is what you want to persue. If you want to go that route, I'd suggest a separate box with Snort-inline installed, placing it before your IPCop box (on the network).

Please take what I say with somewhat of a grain of salt, as I've never installed an IPS before. The setup is quite different than an IDS (which I do have experience with), from what I've read. They may appear similar and Snort-inline may be based off of Snort but setting up Snort-inline doesn't seem to be a trivial install. I don't know the hardware specs of your IPCop machine, but a box that inspects packets at the level of an IDS PLUS performs routing and firewalling duties would definitely have to be beefy, especially if you're using it in an environment that will track lots of traffic.

Just my .02
 
Old 08-24-2007, 05:32 AM   #8
Peter_APIIT
Member
 
Registered: Dec 2006
Posts: 606

Rep: Reputation: 31
Thanks for your help. Where can i download the rules and how do i upload to IpCOP ?
 
Old 09-27-2007, 03:35 PM   #9
archtoad6
Senior Member
 
Registered: Oct 2004
Location: Houston, TX (usa)
Distribution: MEPIS, Debian, Knoppix,
Posts: 4,727
Blog Entries: 15

Rep: Reputation: 234Reputation: 234Reputation: 234
unixfool, vis-à-vis that bake off:
  • Which vers. of each were you using?
  • Who won?
  • Why?
I ask because I have been running SmoothWall Express (SWE) 2.0 for about 3 years, but last weekend I did a public demonstration of SWE 3.0 side-by-side w/ IPCop 1.4.16. As a result I am convinced that I want to upgrade my SWE 2.0, but I'm undecided between SWE 3.0 & IPCop. I would appreciate your input.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Keep track of logs to find suspicious activity leosgb Linux - Security 3 03-04-2006 06:09 PM
Need IPCop to IpCop VPN assistance Freddde Linux - Networking 1 09-15-2005 02:28 PM
Suspicious hard drive activity machinemanagement Red Hat 4 08-25-2005 03:28 PM
suspicious log activity hoedad Linux - Newbie 3 07-26-2004 07:33 AM
Stopping suspicious ICMP activity tarballedtux Linux - Security 1 02-03-2002 07:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:21 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration