Snort - block IP on Mikrotik RouterOS

Hi!

Just installed Snort on a separate machine and was wondering, if there’s a way to block IP Connections or Adresses on Mikrotik Routerboard if Snort creates an alert?

Just like SnortSAM.

With packet sniffer all the traffic from the routerboard can be sent to the snort-machine, that works well.

But then I only have an IDS, not an IPS :slight_smile:

Or is there another useful IPS that can be run on Routerboard?

Tzhanks in advance.

You can make Snort machine so that it logs in to the router via API (or some other method) and create firewall rules based on the alert.