No, this isn't anything like snort, though snort is helpful in determining what to block.  Policy-based routing is actually a way of the router looking at the IP traffic itself and doing stuff to/with it before you let it head on to its destination.  This is a step that happens before the K12LTSP server--or anything else on the LAN--ever sees the traffic.

As for an example, yes, I could...on a router, specifically, a cisco, because that's how we do it (we use ciscos for lots of esoteric--er, "creative" things).  I don't know how to do it on another router type, though, and I'd be lost on how to do it on a GNU/Linux router, until I can take some time to research it.  Should be conceptually the same, though, if policy routing's supported, but I just haven't done it on GNU.

Mind you, though, you'd better have a decent understanding of what policy-based routing is before you even think of applying it.  You could easily DoS yourself.

If, after all these warnings, you are still interested, and I hope you are because it's very useful, let me know, and I'll be glad to help you offline.  For now, check out this bit of short (really!) reading:


This describes Code Red, but you'd simply add the strings "login.oscar.aol.com" and "*messaging.aol.com" to the list of things to look for, and you've killed it.


