PF log parser and dynamic PF rules...

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Per-Olov Sjöholm
Date: Tuesday, February 16, 2010 - 2:22 am

Hi "misc"

I am looking for a tool to use as a trigger for dynamically open PF ports from
certain IP:s.

I will access non critical info but want at least a port knocker as security.

If I access an IP on my DMZ that is not in use on a port that is fake I want
to dynamically add a PF rule for a totally different purpose. Let's say I
access http://1.2.3.4:45321 which is blocked and logged in PF, what is the
easiest way to create a trigger from the PF log or the PF log device?

A cron job with grep in the PF log and then run pfctl to add the rule is from
many points of view a bad choice... I don't want to dig through the PF log as
it can be huge, and I don't want to use a cron job as it takes to long..

Any suggestions appreciated.


Thanks in advance
/Per-Olov
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 2:22 am)
Re: PF log parser and dynamic PF rules..., Bret S. Lambert, (Tue Feb 16, 2:25 am)
Re: PF log parser and dynamic PF rules..., Bret S. Lambert, (Tue Feb 16, 2:30 am)
Re: PF log parser and dynamic PF rules..., Claudio Jeker, (Tue Feb 16, 2:40 am)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 2:53 am)
Re: PF log parser and dynamic PF rules..., Lars Nooden, (Tue Feb 16, 3:11 am)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 3:15 am)
Re: PF log parser and dynamic PF rules..., Peter N. M. Hansteen, (Tue Feb 16, 3:17 am)
Re: PF log parser and dynamic PF rules..., Bret S. Lambert, (Tue Feb 16, 3:17 am)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 3:28 am)
Re: PF log parser and dynamic PF rules..., Bret S. Lambert, (Tue Feb 16, 3:35 am)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 3:39 am)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 3:44 am)
Re: PF log parser and dynamic PF rules..., Lars Nooden, (Tue Feb 16, 3:44 am)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 3:57 am)
Re: PF log parser and dynamic PF rules..., Jussi Peltola, (Tue Feb 16, 4:03 am)
Re: PF log parser and dynamic PF rules..., Peter N. M. Hansteen, (Tue Feb 16, 4:06 am)
Re: PF log parser and dynamic PF rules..., Lars Nooden, (Tue Feb 16, 4:06 am)
Re: PF log parser and dynamic PF rules..., Bret S. Lambert, (Tue Feb 16, 4:07 am)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 4:25 am)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 4:27 am)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 4:41 am)
Re: PF log parser and dynamic PF rules..., Bret S. Lambert, (Tue Feb 16, 4:43 am)
Re: PF log parser and dynamic PF rules..., Peter N. M. Hansteen, (Tue Feb 16, 4:52 am)
Re: PF log parser and dynamic PF rules..., Bret S. Lambert, (Tue Feb 16, 6:28 am)
Re: PF log parser and dynamic PF rules..., Floor Terra, (Tue Feb 16, 6:34 am)
Re: PF log parser and dynamic PF rules..., Eugene Yunak, (Tue Feb 16, 9:17 am)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 4:40 pm)
Re: PF log parser and dynamic PF rules..., Paul de Weerd, (Tue Feb 16, 4:57 pm)
Re: PF log parser and dynamic PF rules..., Randal L. Schwartz, (Tue Feb 16, 6:07 pm)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Tue Feb 16, 11:51 pm)
Re: PF log parser and dynamic PF rules..., Kenneth R Westerback, (Wed Feb 17, 4:31 am)
Re: PF log parser and dynamic PF rules..., Peter Hessler, (Wed Feb 17, 4:38 am)
Re: PF log parser and dynamic PF rules..., Per-Olov Sjöholm, (Wed Feb 17, 1:56 pm)