Re: Snort & iptables on the same box

From: Joachim Schipper (j.schipper_at_math.uu.nl)
Date: 06/13/05

  • Next message: H B: "Evaluating various NIPS"
    Date: Mon, 13 Jun 2005 10:01:47 +0200
    To: focus-ids@securityfocus.com
    
    

    On Fri, Jun 10, 2005 at 05:04:28PM -0400, Jean-Pierre Denis wrote:
    > Hi,
    >
    >
    > When running snort and iptables on the same box, which of the 2 act first ?
    >
    > Those it go thru snort and then the iptable rule allow or deny the
    > connection
    > or it's the other way around
    >
    >
    > Merci,
    > JP

    Hi JP,

    Neither 'act first' in a standard configuration; if you use Snort in
    (standard) IDS mode, it sees the packets at the same time as Netfilter
    (the kernel part of IPTables) and acts independently.

    If you use Snort_inline (IPS mode), the packets enter Netfilter, which
    may choose to pass it to Snort_inline via the QUEUE target at some
    point.

    This is all in the snort documentation, BTW.

                    Joachim

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: H B: "Evaluating various NIPS"

    Relevant Pages

    • Re: Value of "richer" signatures?
      ... Snort, Dragon, and NFR, and I can tell you that they ... Here's an example of how the newer IDS signatures help ... Let's say you are using a simple packet grepping IDS ... > an FTP connection). ...
      (Focus-IDS)
    • Re: ids inquisition
      ... Subject: ids inquisition ... Snort isn't one of them. ... Brian Caswell - CSV output plugin, ... Christian Lademann - active response, ...
      (Focus-IDS)
    • RE: IDS recommendations
      ... Subject: IDS recommendations ... Snort is a relatively raw tool and that usually adds ... >> I can appreciate your comments on the ISS product. ...
      (Focus-IDS)
    • RE: "Free" IDS
      ... I am very surprised noone mentioned Demarc PureSecure IDS solution. ... It cost less than 2000.00 and it runs off of the snort engine and has a big ... if you want to learn snort then just read up on it. ...
      (Focus-IDS)
    • RE: Test tools for IDS
      ... "Sneeze" is great for Snort IDS. ... Captus Networks IPS 4000 ... Intrusion Prevention and Traffic Shaping Technology to: ...
      (Focus-IDS)