nanog mailing list archives
Blocking nimda probes with a content-layer switch
From: Joe Abley <jabley () automagic org>
Date: Wed, 19 Sep 2001 00:32:50 -0400
Has anybody tried to block nimda HTTP GET probes using URL pattern matches in a "layer-4-7"[1] switch? The ideal result is to prevent nimda GET probes from ever reaching the destination address, but causing the session to be reset towards the server after the open handshake but before the GET can be sent to the server would be acceptably useful. Particularly whether it's possible on a cisco/Arrowpoint switch, but it would be interesting to know about other vendors too. Please reply directly, will summarise if there are answers to share. Thanks! [1] substitute phrase-du-jour as appropriate
Current thread:
- Blocking nimda probes with a content-layer switch Joe Abley (Sep 18)
- procmail nimda e-mail filter Bryan Bradsby (Sep 18)
- Re: Blocking nimda probes with a content-layer switch Lincoln Dale (Sep 19)
- Re: Blocking nimda probes with a content-layer switch jeff (Sep 19)
