portsentry는 백그라운로 돌아가는 것이죠...
nmap것이 스캔을 하면... root에게 메일로 알려주는 프로그램입니당..
설정을 잘하면 스캔을 한곳은 다시 접근 못하게 할 수 도 있는 것으로..
대개 TCP stealth scan detection mode & UDP scan detection mode로
rc.local 파일에다 다음을 첨가하죠..
/설치한곳/portsentry -atcp
/설치한곳/portsentry -sudp
그래야 항상 검사를 하죠..
설명이 되었나요..?