Filtre ip psad

Hello

Je voudrai savoir s’il y a une alternative a snort qui est un peux lourd!

quelque chose qui me permette de plenter un ban sur une ip pour x ou Y raison voire qu’il le fasse automatiquement ,si c est en interface graphique sa serai nikel.

pour l’instant j’ai vu psad , mai il y a peut d’information et sa me semble etre uniquement en console.

Des idées ?

[code]console@MAT64LIN:/usr/src/linux$ aptitude show fail2ban
Package: fail2ban
New: yes
State: not installed
Version: 0.7.5-2
Priority: optional
Section: net
Maintainer: Yaroslav Halchenko debian@onerussian.com
Uncompressed Size: 500k
Depends: python2.4, python-central (>= 0.5.8), python (>= 2.4), iptables, lsb-base (>= 2.0-7)
Suggests: python-gamin, mailx
Description: bans IPs that cause multiple authentication errors
Monitors log files (e.g. /var/log/auth.log, /var/log/apache/access.log) and temporarily or persistently bans failure-prone
addresses by updating existing firewall rules. The software was completely rewritten at version 0.7.0 and now allows easy
specification of different actions to be taken such as to ban an IP using iptables or hostsdeny rules, or simply to send a
notification email. Currently, by default, supports ssh/apache/vsftpd but configuration can be easily extended for
monitoring any other ASCII file. All filters and actions are given in the config files, thus fail2ban can be adopted to be
used with a variety of files and firewalls.

Homepage: http://www.sourceforge.net/projects/fail2ban

Tags: admin::logging, admin::monitoring, interface::commandline, role::program, security::ids, security::log-analyzer
[/code]mais ça n’a aucune interface graphique.