Daniel Weismüller wrote: Hi Daniel, > Hi Rob, > > did you see Guardian? > In my opinion it does nearly the same. > I had looked at Guardian in the past but as I thought it was tied closely with snort I had not paid it much much attention. I've had another look and see it has an 'Ignored Hosts' facility so I tried adding a blocking entry. I'm sure it blocks but it doesn't generate iptable rules so its operation is rather unclear to me. Thank you for the pointer but I am much happier with the way I am familiar with YMMV! Kind Regards Rob