Op donderdag 15 november 2001 16:13 schreef Jotti het volgende:
En ik ga niet ruziën met users

Ik quote gewoon een stukje uit datzelfde artikel op linuxsecurity.com.
Fair is fair, dus backquote ik wat uit dat artikeltje

It is stupid to use such counter measures as to dynamically block a host that appears to be port scanning. The source IP of a scan can be faked to fool Port Sentry into blocking an arbitrary host (for example localhost or the routing machine for the Port Sentry machine, effectively DOSsing your machine), a large number of faked source IPs can destroy your machines static routing table or fill your firewall rule table to the point that it can bearly run (There is a similar note in the nmap man page under the -D decoy section, I can't help but think that fyodor is sneering at Port Sentry in particular).
[..]
This is a poor piece of software and I can't help but think that its only reasons for success are because of the placebo that it proactively responds to scans and the fact that it was written by a security company. It may be passable for the home user but you'd be a fool to run it on any large commercial network.
Op donderdag 15 november 2001 17:18 schreef wouzer het volgende:
Ik ga ook niet ruziën, maar als je een goeie firewall hebt die blokkeerd wat hij moet blokkeren, wat boeit het dan wie pogingen doen om te scannen. Portsentry en snort enzo is leuk allemaal, maar een goeie firewall doet ook wonderen. Een firewall kan ook loggen btw.

Tja, een NIDS is geen firewall en er ook geen vervanging voor. Het is wel verrekte handig om te controleren of je firewall goed dicht zit (een firewall logt normaal geen packets die hij niet dropped).