Snort mailing list archives

RE: Snort + ipchains


From: "Martijn Heemels" <martijn () heemels com>
Date: Sat, 1 Dec 2001 19:05:47 +0100

 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

As a side note: snort sees packets that ipchains DENY's or
REJECT's, so  I don't see why you don't just run ipchains *and*
snort and be 
done with it.


It doesn't for everyone. In fact, according to the snort faq for most
people ipchains does block traffic to snort (including me). So he may
not be able to do this.

Greets, Martijn

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBPAkb+hLMC0rbivl4EQKR+wCeOIQnDCq3F1GCofi0n1HM3UUXR5IAn1s8
ztA+2VO+CEqe0tmq7Mje/hat
=DjAb
-----END PGP SIGNATURE-----

Attachment: smime.p7s
Description:


Current thread: