Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-IDS
[Top] [All Lists]

Re: Snort inline and iptables

Subject: Re: Snort inline and iptables
Date: Tue, 23 Aug 2005 11:43:01 +0530
Hi all,

1- can i use snort inline+iptables in router (no bridge) mode under linux?
--yes ,we can do soo.

more help on setup: http://linuxgazette.net/117/savage.html
2- what's the performance issuses when using snort inline + flexresponse mode?


--i my view performance issues are more.although if you have a good processer and good configuration still it depends on the traffic.

Regards,
Ratna Kumar
Visual Soft Technologies Ltd

----- Original Message ----- From: "Soi, Dhruv" <dsoi@ipolicynetworks.com>
To: <afshinlamei@gmail.com>; <focus-ids@securityfocus.com>
Sent: Monday, August 22, 2005 4:04 PM
Subject: RE: Snort inline and iptables




Dear all,

1- can i use snort inline+iptables in router (no bridge) mode under linux?
Snippet copied from one of the mail that I received from mailing list.
-------------------------------------------------------
There are active-response modules for Snort available.

Snort can do content-detection; with active response, the packets could
be dropped / filtered / redirected.

Michael T. Babcock
Triple PC Ltd.
-------------------------------------------------------


To use it with IPTABLES you need to patch the kernel and netfilter to support Hex search.


Thanks
Dhruv

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
to learn more.
------------------------------------------------------------------------





------------------------------------------------------------------------ Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it with real-world attacks from CORE IMPACT.
Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 to learn more.
------------------------------------------------------------------------


<Prev in Thread] Current Thread [Next in Thread>