Snort mailing list archives

Re: snort and iptables


From: Tony Robinson <deusexmachina667 () gmail com>
Date: Wed, 14 Nov 2012 17:23:40 -0500

I just thought I would pop in say that this document is VERY informative
and gives a greater understanding as to the purpose of the DAQ. It does a
nice job augmenting the DAQ documentation in the snort manual.

Cheers,

DA

On Wed, Nov 14, 2012 at 6:48 AM, Peter Bates <peter.bates () ucl ac uk> wrote:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Hello all

On 14/11/2012 11:28, amin Salehi wrote:
hi.what is the relationship between snort in inline mode and iptables?

The following appeared at the SANS reading room recently:

http://www.sans.org/reading_room/whitepapers/detection/analysis-snort-data-acquisition-modules_34027

- - it might be worth a read.

- --
Peter Bates
Senior Information Security Officer   Phone: +44(0)2076792049
Information Services Division         Internal Ext: 32049
University College London
London WC1E 6BT
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.17 (MingW32)
Comment: Using GnuPG with Mozilla - http://www.enigmail.net/

iQEcBAEBAgAGBQJQo4T8AAoJELhVoVpEMS6RYQEH/0uF0+7UpRG6PUpo5fh1pkRE
a/TmCojMKNzA/2Yi3gwzen3ebqABiH9fo7zXnEJNTW+roLTwuHdo5GMVrbrnVcGS
ZKM/11DXX1PCiLsaHO+8B3OZIwxpwaVahblGwC4d+N2YujVJvyAQWgRbHjLGvjBt
DAadFaaGtIhg0X1F8Qm14yq8TNPXsbrvH7V56R0Ta1ztvpA6ysJPHdu7GT7psQKC
52XqO+oEt5yJOgID/eAQqKkBtmo/dtJWJKSFgVIW61ZbGiy+lgP8bQS1zi6D7nvu
3YEHyUdn05bg201aTFDjCQC79r0NGNvhHaAnR2B9Nw+ZwTTMKZuLacNmvL/1GYs=
=KUa6
-----END PGP SIGNATURE-----



------------------------------------------------------------------------------
Monitor your physical, virtual and cloud infrastructure from a single
web console. Get in-depth insight into apps, servers, databases, vmware,
SAP, cloud infrastructure, etc. Download 30-day Free Trial.
Pricing starts from $795 for 25 servers or applications!
http://p.sf.net/sfu/zoho_dev2dev_nov
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest
Snort news!




-- 
when does reality end? when does fantasy begin?
------------------------------------------------------------------------------
Monitor your physical, virtual and cloud infrastructure from a single
web console. Get in-depth insight into apps, servers, databases, vmware,
SAP, cloud infrastructure, etc. Download 30-day Free Trial.
Pricing starts from $795 for 25 servers or applications!
http://p.sf.net/sfu/zoho_dev2dev_nov
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: