I think portsentry does almost exactly what he wants. Snortsam manipulates firewall rules (optionally on multiple hosts/firewalls) and is quite a bit more work to set up if I recall from when I looked at it. The largest requirement is to have a working snort install which he may not have.
alex _______________________________________________
Nope, not snortin for this particular net
-- Robert - Abba Communications Computer & Internet Services (509) 624-7159 - www.abbacomm.net