On Sun, Apr 16, 2006 at 06:34:37PM -0400, Martin Hicks wrote: > > > > - so rule one sets things up for me. > - Rule two says "if you get four connections to TCP port 22 in a 60 second > window then log it" > - Rule three says "if you get four connections to TCP port 22 in a 60 second > window then drop the packet." Sorry, that was fairly poorly explained. Its also "from a specific IP address" mh -- Martin Hicks || mort [ at ] bork [ dot ] org || PGP/GnuPG: 0x4C7F2BEE