Pfsense + Snort: Detecting a DoS on your Network

Опубликовано: 28 Сентябрь 2024
на канале: Simplificando Redes
5,557
132

We present a way to detect a type of denial of service (DoS) flood attack within the network. For this example, the attack is within the network and is directed at another machine on the internal network.


Snort acts as an IPS when it detects that an attack is taking place within the network, alerts and then blocks the attacker's address. In this scenario Pfsense is on the way to the Internet, so a machine on the blocked internal network is prevented from accessing the Internet.


Professor Dalbert


#Snort #Pfsense #DoS


Snort rule to detect DoS:
English:
https://simplificandoredes.com/en/sno...



Português:
https://simplificandoredes.com/snort-...


00:00 Start
00:15 Card with video about the attack
00:56 Configuration
04:00 Creating the rule to detect DoS
09:55 Starting the DoS tool for testing
10:30 Checking Snort Alerts