Re: Generic content filter available?

From: Erik (erik@geenspam.vanwesten.net)
Date: 03/24/02


From: Erik <erik@geenspam.vanwesten.net>
Date: 24 Mar 2002 12:30:59 GMT

mpsarros@iiic.ethz.ch wrote:

> The company I work for wants to add a "content filter" before the host
> system for protecting it against crack and DOS Attacks.
> This would be just a server with accepts connection only at a specific
> port where the data for the host would be send (acting like a normal
> firewal) but it would also control the data that comes to this port
> for their correctnes and specification compliance (something like
> "proxy", "content filter" or how it could be also called).

> Until now I have only found http-proxys but our protocol is plain TCP/IP
> not build upon http. So I would like to ask if there exist such generic
> filters or at least a framework as I don't want to reinvent the wheel...
> If nothing like that exists, would it be easy to implement one by
> rewriting an existing http-proxy? Which one would you suggest?

> The whole thing should be running on Solaris, FreeBSD or Linux. Windows
> is too unsecure, closed and propiertary to be taken into consideration :-)

> thanks for any advice
> Michael Psarros <mpsarrosATvis.ethz.ch>

Have a look at hogwash <http://hogwash.sourceforge.net>. This might be
exactly what you are looking for. Downside: not officially stable yet.

It is based on a bridge which does _not_ run a tcp/ip stack, and is
snort based. Very very hard to bypass.

EJ

-- 
For OpenBSD pf en nat rule examples: http://www.vanwesten.net 



Relevant Pages

  • Re: Still cant connect to RWW or OWA remotely
    ... it certainly appears to be something about the SBS configuration. ... Meridian.local Ethernet adapter Local Area Connection: ... Windows SMALL BUSINESS SERVER 2003 Windows IP Configuration ... 192.168.254.254) directly to a port on the router and then ...
    (microsoft.public.windows.server.sbs)
  • Re: Still cant connect to RWW or OWA remotely
    ... it certainly appears to be something about the SBS configuration. ... Meridian.local Ethernet adapter Local Area Connection: ... Windows SMALL BUSINESS SERVER 2003 Windows IP Configuration ... 192.168.254.254) directly to a port on the router and then ...
    (microsoft.public.windows.server.sbs)
  • RE: VBscript Error on SBS2k3
    ... DHCP Server turned of SonicWALL with VPN Pass through request for IP to ... the problem should be caused by the 4125 port. ... > | Accessories and Communications and Remote Desktop Connection? ... > | 2.In Internet Explorer on the workstation you are connecting from, ...
    (microsoft.public.windows.server.sbs)
  • Re: interfaces lo:1 lo:2 lo:3? (for remote ssh tunnels)
    ... That's the problem tunneling (port forwarding) solves. ... >>can't get past the client firewall. ... > I don't understand why the server would be making the ... server initiates another connection to the client -- in this ...
    (Debian-User)
  • Re: Can not access Web and FTP sites from Internet
    ... your IP Configuration on the Server is correctly. ... Connecting To 12.208.215.87...Could not open connection to the host, ... 1> From the result, we can see the telnet failed, which means the router ... does not forward Port 443 to SBS Server. ...
    (microsoft.public.windows.server.sbs)