<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Layer7 Rules can close connections?]]></title><description><![CDATA[<p dir="auto">Hi,<br />
I've been trying to filter some http packets that come with this form "GET /0.XXX" and it's filtering the packets very well using this pattern code:</p>
<blockquote>
<p dir="auto">http-botnet1<br />
/\x3f0\x2e[0-9]<em>.</em></p>
</blockquote>
<p dir="auto">This blocks all the packets, but what I truly want is that if a packet with that form if recived, the connection should be closed.</p>
<p dir="auto">Is there a way to do that?</p>
]]></description><link>https://forum.netgate.com/topic/55992/layer7-rules-can-close-connections</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Jul 2026 08:36:48 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/55992.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 05 May 2013 07:09:36 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Layer7 Rules can close connections? on Wed, 15 May 2013 23:08:25 GMT]]></title><description><![CDATA[<p dir="auto">IT just blocks the whole connection if a packet that matches is received.<br />
Not whole packets.</p>
]]></description><link>https://forum.netgate.com/post/395784</link><guid isPermaLink="true">https://forum.netgate.com/post/395784</guid><dc:creator><![CDATA[eri--]]></dc:creator><pubDate>Wed, 15 May 2013 23:08:25 GMT</pubDate></item><item><title><![CDATA[Reply to Layer7 Rules can close connections? on Fri, 10 May 2013 19:10:34 GMT]]></title><description><![CDATA[<p dir="auto">I say you probably want to look into snort for this sort of stuff</p>
]]></description><link>https://forum.netgate.com/post/394998</link><guid isPermaLink="true">https://forum.netgate.com/post/394998</guid><dc:creator><![CDATA[SeventhSon]]></dc:creator><pubDate>Fri, 10 May 2013 19:10:34 GMT</pubDate></item></channel></rss>