Networking Forums

Networking Forums > Computer Networking > Linux Networking > Black Hole / Sink Hole Routing

Reply
Thread Tools Display Modes

Black Hole / Sink Hole Routing

 
 
Cameron Kerr
Guest
Posts: n/a

 
      07-13-2004, 04:08 AM
Awie <(E-Mail Removed)> wrote:

> I applied black hole / Sink hole routing to our Cisco router that redirect
> all packets that have known "virus/worm" pattern to null device. It is very
> helpfull to drop all packets that contain NIMDA, NACHI, etc
>
> Is it possible to do the same action by using IPTABLES?
>
> Your answer is very appreciated and waited for.


Have a look at
http://www.linuxsecurity.com/feature...story-148.html

Or search for 'iptables content match OR filter'

You could mark the packets, then use iproute to route them to a dummy
interface.

--
Cameron Kerr
(E-Mail Removed) : http://nzgeeks.org/cameron/
Empowered by Perl!
 
Reply With Quote
 
 
 
 
Awie
Guest
Posts: n/a

 
      07-13-2004, 06:31 AM
All,

I applied black hole / Sink hole routing to our Cisco router that redirect
all packets that have known "virus/worm" pattern to null device. It is very
helpfull to drop all packets that contain NIMDA, NACHI, etc

Is it possible to do the same action by using IPTABLES?

Your answer is very appreciated and waited for.

Thx & Rgds,

Awie
 
Reply With Quote
 
Awie
Guest
Posts: n/a

 
      07-14-2004, 03:45 PM
Cameron Kerr <(E-Mail Removed)> wrote in message news:<(E-Mail Removed)>...
> Awie <(E-Mail Removed)> wrote:
>
> > I applied black hole / Sink hole routing to our Cisco router that redirect
> > all packets that have known "virus/worm" pattern to null device. It is very
> > helpfull to drop all packets that contain NIMDA, NACHI, etc
> >
> > Is it possible to do the same action by using IPTABLES?
> >
> > Your answer is very appreciated and waited for.

>
> Have a look at
> http://www.linuxsecurity.com/feature...story-148.html
>
> Or search for 'iptables content match OR filter'
>
> You could mark the packets, then use iproute to route them to a dummy
> interface.


Thanks Cameron. I will visit the site.

Best Rgds,

Awie
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
NAT hole punching Tobias Nissen Linux Networking 3 02-06-2010 03:02 PM
'That' Firefox Security Hole.... Spamtastic Spastic Broadband 0 09-12-2009 07:54 PM
Where is the black hole? kevin bailey Broadband 0 04-19-2007 05:00 PM
Is a repeater a security hole? svl2706 Wireless Internet 6 04-27-2006 12:08 PM
Why more than 1 hole in FW for IPSec =?ISO-8859-15?Q?Ren=E9_Matth=E4i?= Linux Networking 17 09-02-2003 04:16 AM



1 2 3 4 5 6 7 8 9 10 11