Snort mailing list archives

Re: snort+iptables


From: Mitesh Jadia <mitesh.jadia () gmail com>
Date: Thu, 8 Nov 2012 00:16:22 +0530

Yes it is possible. Create nfqueue target rules in firewall.
In snort use daq_nfq module as packet source.

Regards,
Mitesh



On 07-Nov-2012, at 11:04 PM, Leonardo Pezente <lmpezente () gmail com> wrote:

well, i was tring to use snort on IPS mode, but i had another idea, use iptables firewall and snort together.
but im not sure if snort can see and alert any drop from iptables. Is that possibles?

Like, if some one try one dos, and i drop the attack packets, am is snort able to alert the dos?
If so, how can i do that?
------------------------------------------------------------------------------
LogMeIn Central: Instant, anywhere, Remote PC access and management.
Stay in control, update software, and manage PCs from one command center
Diagnose problems and improve visibility into emerging IT issues
Automate, monitor and manage. Do more in less time with Central
http://p.sf.net/sfu/logmein12331_d2d
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

------------------------------------------------------------------------------
LogMeIn Central: Instant, anywhere, Remote PC access and management.
Stay in control, update software, and manage PCs from one command center
Diagnose problems and improve visibility into emerging IT issues
Automate, monitor and manage. Do more in less time with Central
http://p.sf.net/sfu/logmein12331_d2d
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: