Snort mailing list archives
Re: Block
From: Matt Kettler <mkettler () evi-inc com>
Date: Tue, 17 Feb 2004 11:02:38 -0500
At 10:48 PM 2/16/2004, Brian wrote:
> 2) snort-inline > - linux kernel specific at the moment, but does true kernel-level > firewall interaction as packets arrive. IIRC, snort-inline works on FreeBSD as well, using divert sockets.
Brian, I don't think that the FreeBSD code is considered stable yet. I could be wrong, but there's nothing on the project page or mailing list to indicate otherwise.
Looking at their mailing list archives they got their first user to test it on 1/12/04.
So, while the code exists, and it should work, it's still quite new and hasn't had much more than a month of testing.
I'd give the FreeBSD version a try on a test box, but I don't think I'd quite consider it for a production system.. at least not yet..
------------------------------------------------------- SF.Net is sponsored by: Speed Start Your Linux Apps Now. Build and deploy apps & Web services for Linux with a free DVD software kit from IBM. Click Now! http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Re: Snort logging way too much, (continued)
- Re: Snort logging way too much Martin Roesch (Feb 13)
- Re[2]: Snort logging way too much Ochronus (Feb 13)
- Re: Block Frank Knobbe (Feb 16)
- Re: Block Brian (Feb 16)
- Re: Block Matt Kettler (Feb 17)
- Re: Snort logging way too much Martin Roesch (Feb 13)