Snort mailing list archives

Re: 2.3RC2, inline, faq?


From: slesru <slesru () yahoo com>
Date: Tue, 4 Jan 2005 22:07:49 -0800 (PST)


--- Will Metcalf <william.metcalf () gmail com> wrote:

Did you apply iptables p-o-m to your kernel sources?
 The problem is
snort reading packets from ip_queue in the IpqLoop
in inline.c, not
something that can be fixed with changes to your
snort_inline.conf....

cat /proc/net/ip_queue 

and send us back your results......

Hello!
I didn't applied any patches to kernel (as I wrote
this is kernel from Suse, not from kernel.org, I'll
test another kernel..)

Here is my ip_queue (when snort is started)

Peer PID          : 4068
Copy mode         : 2
Copy range        : 65535
Queue length      : 1
Queue max. length : 1024




                
__________________________________ 
Do you Yahoo!? 
Yahoo! Mail - 250MB free storage. Do more. Manage less. 
http://info.mail.yahoo.com/mail_250


-------------------------------------------------------
The SF.Net email is sponsored by: Beat the post-holiday blues
Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek.
It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: