Re: Firewall open source + IPS

On Viernes 10 Julio 2009 13:00:47 Juan B escribió:
Hi all,

Im looking for an FW open source which includes IPS, I know that IPCop has
one but its and ids and not IPS.

any ideas??

many... depends on your requirement.

fwsnort: Is a string patter detection tool that can be mixed with iptables.
fwsnort is an option, i don't test it before, but be careful on fragmentation

Snort can be configured as IPS with iptables triggers (snort_inline: But this configuration have some issues
and you need to be extra-careful.

thanks !


