The security/snort2pf port
snort2pf-4.5p7 – block "nasty" hosts with pf(4) based on Snort's rules (cvsweb github mirror)
Description
Snort2Pf is a small Perl daemon which greps Snort's alertfile and blocks the "naughty" hosts for a given amount of time using pfctl.WWW: https://sourceforge.net/projects/snort2pf/
Readme
+-----------------------------------------------------------------------
| Running ${PKGSTEM} on OpenBSD
+-----------------------------------------------------------------------
Adjusting pf.conf(5)
====================
In order to make use of snort2pf, one must add an anchor for in your pf.conf(5)
file, like:
anchor snort2pf
Or you can use a table, which is allows for more flexibility:
block in quick from
Maintainer
The OpenBSD ports mailing-list
Categories
Run dependencies
Files
- /etc/rc.d/snort2pf
- /usr/local/man/man8/snort2pf.8
- /usr/local/man/man8/snort2pfmon.8
- /usr/local/sbin/snort2pf
- /usr/local/sbin/snort2pfmon
- /usr/local/share/doc/pkg-readmes/snort2pf
- /var/log/snort/
- @exec-add touch /var/log/snort/alert
- @extraunexec rm -f /var/log/snort/alert