Snort mailing list archives

Re: 2.3RC2, inline, faq?


From: slesru <slesru () yahoo com>
Date: Tue, 4 Jan 2005 23:02:25 -0800 (PST)


--- Will Metcalf <william.metcalf () gmail com> wrote:

Did you apply iptables p-o-m to your kernel sources?
 The problem is
snort reading packets from ip_queue in the IpqLoop
in inline.c, not
something that can be fixed with changes to your
snort_inline.conf....

cat /proc/net/ip_queue 

and send us back your results......

I just compiled 2.6.10 from kernel.org.
The same problem.
Here is ip_queue for this kernel:

Peer PID          : 5929
Copy mode         : 2
Copy range        : 65535
Queue length      : 2
Queue max. length : 1024



                
__________________________________ 
Do you Yahoo!? 
All your favorites on one personal page – Try My Yahoo!
http://my.yahoo.com 


-------------------------------------------------------
The SF.Net email is sponsored by: Beat the post-holiday blues
Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek.
It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: