Snort mailing list archives

RE: Fw: problem with snort inline -unknown option - Q


From: "Slighter, Tim" <tslighter () itc nrcs usda gov>
Date: Fri, 25 Apr 2003 09:57:04 -0600

Try re-configuring snort-inline this way

./configure --enable-snort-inline and with nothing else and then modprobe
the ip_queue first and run snort-inline.  Many people have had issues
getting things working when configuring with --enable-snort-inline and
--with-mysql.

Also one other thought, did you download and install the latest iptables
source from netfilter?

-----Original Message-----
From: parikshit [mailto:parikshit () elitecore com]
Sent: Thursday, April 24, 2003 11:16 PM
To: Slighter, Tim; snort-users () lists sourceforge net
Subject: Re: [Snort-users] Fw: problem with snort inline -unknown option
-Q


Hello,

Now I am able to load the module ip_queue ..

still snort-inlinne cries foul .

 invalid option --Q

I am configuring snort-inline

./configure --with-mysql=/usr/include/mysql --prefix=/usr/local/snort  --ena
ble-inilne --with-libipq-includes=/usr/include --with-libipq-libraries=/root
/netfilter/userspace/libipq

make
make install

 all successful.

Still snort-inline dies..

I hope   I am making a silly mistake.
-Parikshit



----- Original Message -----
From: "Slighter, Tim" <tslighter () itc nrcs usda gov>
To: "'parikshit'" <parikshit () elitecore com>;
<snort-users () lists sourceforge net>
Sent: Friday, April 25, 2003 12:31 AM
Subject: RE: [Snort-users] Fw: problem with snort inline -unknown option -Q


do you have the modprobe for ip_queue enabled?  /sbin/modprobe ip_queue

then run snort-inline

-----Original Message-----
From: parikshit [mailto:parikshit () elitecore com]
Sent: Thursday, April 24, 2003 6:48 AM
To: snort-users () lists sourceforge net
Subject: [Snort-users] Fw: problem with snort inline -unknown option -Q



----- Original Message -----
From: "parikshit" <parikshit () elitecore com>
To: <mailto:snort-users@lists.sourceforge>
Cc: <parikshit () elitecore com>
Sent: Thursday, April 24, 2003 11:09 AM
Subject: problem with snort inline -unknown option -Q


Hello  nice people,

 I am facing problem in configuring , compiling and running
snort-inline
.

 Previously it was ip_queue which was dying.  Now it is okay with
ip_queue
module of iptables.

 I have snort-inline.tgz from snort . I configure and make it
ith  --enable-inline
 --with-mysql --with-libipq-includes=MYINCLUDEPATH  --with-libipq-librarie
s=
MYLIBPATH

 snort-inline gets compiled.. and  build ---this is okay..

 but when I run snort-inline
   snort-inline -D -d -c SNORT-INLINE-CONF-PATH -Q -i eth0


 snort is dying .....

 /usr/local/bin/snort: invalid option -- Q


 What should I do ?

  I am in such a network ,where the machine on which snort-inline will
run
is being shared by a bunch of developers too.  I can't block all the
traffic
from  my internal LAN.

 can anyone give me a sage rc.firewall  variant ?


 Thank you very much in advance.

 -Parikshit.


Regards
Parikshit






-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: