Snort mailing list archives
Re: Snort-inline question
From: Alberto Gonzalez <albertg () cerebro violating us>
Date: Tue, 31 Dec 2002 01:37:47 -0800
I personally haven't used snort-inline. But Hogwash doesn't use iptables to drop packets. If you successfully compiled snort-inline then your good to go. IIRC it will only drop packets
in NIDS mode[1], not sniffing mode etc...... Cheers, Alberto Gonzalez [1] Which seems the logical thing todo.. or no? Amit Kumar Gupta wrote:
Hi List,I am having some queries abtSnort-inline. Here they are :- (1) While installing snort-inline whether i have to mention libipq directorty. If i don't mention, even then it goes fine. Does it mean that it has taken it from the appropriate path.(2) snort-inline has the hogwash functionality. So does it mean thatit uses iptables. Another thing is Snort-inline is supposed to sit inlineand prevent malicious packets. How does it do it. Is there any specific commandfor it to do this.(3) I have successfully installed snort-inline, and using snort commands. So does it mean that whenever i will run snort command in any one of the mode(sniffing, IDS, logging), the malicious packets will be dropped.Please give your suggestions and views.Regards, Amit
-- The secret to success is to start from scratch and keep on scratching. ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort-inline question Amit Kumar Gupta (Dec 30)
- Re: Snort-inline question Alberto Gonzalez (Dec 30)
- <Possible follow-ups>
- RE: Snort-inline question Amit Kumar Gupta (Dec 30)