View Single Post
  #1   (View Single Post)  
Old 30th December 2011
dbach dbach is offline
Port Guard
 
Join Date: Aug 2011
Posts: 23
Default pf.conf output to bruteforce file

Hello All:

I have the following rule in pf.conf:

# bruteforce blocking
block quick from <bruteforce>
pass inet proto tcp to $nic port ssh \
keep state (max-src-conn 10, max-src-conn-rate 5/5 \
overload <bruteforce> flush global)

Where should the bruteforce file be placed and with which permissions to have pf write out information for bruteforced attempts?

Thanks,
Darryl
Reply With Quote