Re: layer7 filtering

From: Phil Regnauld (regnauld_at_catpipe.net)
Date: 06/27/05

  • Next message: Donatas: "Re: layer7 filtering"
    Date: Mon, 27 Jun 2005 09:19:30 +0200
    To: Donatas <donatas@lrtc.net>
    
    

    Donatas (donatas) writes:
    > I wonder if there's any person who did some scripting like
    > application layer analysis with network sniffer (like tcpdump) + apropriate firewall rule generation(like statefull ipfw rules) ?

            You mean this ?

            http://www.hsc.fr/ressources/outils/nstreams/

    Nstreams is a program which analyzes the streams that occur on a
    network. It displays which streams are generated by the users between
    several networks, and between the networks and the outside. It can
    optionally generate the ipchains or ipfw rules that will match these
    streams, thus only allowing what is required for the users, and nothing
    more.

    Nstreams can parse the tcpdump output, or the files generated
    with the -w option of tcpdump. It can also directly sniff
    the data that occurs on the network.

    This product was designed by HSC and coded by Renaud Deraison
    (deraison@cvs.nessus.org), author of the Nessus software.
    It is available for free under GNU license.

    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: Donatas: "Re: layer7 filtering"

    Relevant Pages

    • Re: layer7 filtering
      ... It displays which streams are generated by the users between ... > Nstreams can parse the tcpdump output, ... > the data that occurs on the network. ...
      (freebsd-net)
    • Re: Windows Home Server OS Now on Sale
      ... machines on your network and remote desktop access. ... it streams to ... and it has all the media center functionality. ... then you have a nice backup solution. ...
      (comp.sys.mac.advocacy)
    • TLI t_snd hangs
      ... The blocking t_snd occurs about 20 seconds after the network cable has ... endpoint on Machine A. I have tried polling, ... I have began looking into the kernel for status on either ... me to an example on this or shed some light on accessing streams. ...
      (comp.unix.solaris)
    • I need help trying to stop dropouts
      ... usually network congestion or connection to broadcast server lost. ... The internet broadcaster claims that all their streams are ... So if it's not my network, the problem must either be between Makradio ... The stream is a 128kbs Windows Media stream. ...
      (microsoft.public.windowsmedia.player)
    • Windows Media Player 9 streaming issues
      ... usually network congestion or connection to broadcast server lost. ... The internet broadcaster claims that all their streams are ... So if it's not my network, the problem must either be between Makradio ... The stream is a 128kbs Windows Media stream. ...
      (microsoft.public.windowsmedia)