Snort mailing list archives

Iptables Prerouting chain


From: "Madhav Diwan" <mdiwan () wagweb com>
Date: Wed, 14 Nov 2001 22:21:32 -0500

Does Snort work on packets before or after the prerouting chain in
IPtables? 

in other words what address should i use : the SNAT the DNAt or the Masq
.
 for the HOME ip scheme so that i dont cause myself miscief in the form
of huge alert logs?

what about postrouting : will it have any affect on the IDS at all if i
sniff on the local lan interface as well as on the outside interface at
the same time?

Thanks 

Madhav


Note: The information contained in this message may be privileged and confidential and protected from disclosure.  If 
the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this 
message to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this 
communication is strictly prohibited. If you have received this communication in error, please notify us immediately by 
replying to the message and deleting it from your computer.  Thank you.  Wagner Weber & Williams

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: