IDS snort

it would be nice if we could have something in a mikrotik router, like a snort interface… that translates normale snort change firewall rules to mikrotik firewall rules.

pascal

It depends on how many people need this.

John

I too would like to see this, also perhaps something like kismet.

–Eric

what about being able to import rules from softwares such as PeerGuardian to protect privacy of customers?

Hi,
I have developed an IDS/IPS system for RouterOS.
It is here : http://sourceforge.net/projects/mt-fw-attack/

You need a linux machine to compile and run it.
It collects syslog messages from your’s routeros device (there are instructions on how to use it) and adds the attackers on an address list which you can use to block them.
:slight_smile:

+1 IDS SNORT

+1 !

+1.

mean common sense and “understanding IP networking” (c).
but plenty of “copy-paste examples” floating around Web.
for example this one http://klseet.com/index.php/mikrotik/mikrotik-rb750-750g/mikrotik-rb750-basicfirewallsecurity
kinda missed something like that in default in userfriendly state, with text/UI wizards, like psad/snort/suricate/ebtables had on most desktop Linux distros.