[Snort-users] snort + libradiate + inline?

jon baer security at ...9153...
Tue Sep 16 07:28:05 EDT 2003


hi,

has anyone seen anything like the such where something could be done for
deassociating + blocking clients off a wireless lan?

id think in a chain ur write something like (just an idea):

-A INPUT -s 192.168.0.10 -j DEASSOCIATE

im guessing in snort you'd fit it into the flex-resp/inline response:

drop tcp 192.168.0.10 any -> any any (resp: deassociate;)

im just looking to see if there are other doing anything likewise in terms
of active wireless response.

- jon





More information about the Snort-users mailing list