Re: Snort & iptables on the same box

From: Michael Boman (michael.boman_at_gmail.com)
Date: 06/13/05

  • Next message: David Kee: "RE: on NIDS/NIPS tuning"
    Date: Mon, 13 Jun 2005 13:58:44 +0800
    To: Jean-Pierre Denis <jp@webglobe.ca>
    
    

    On 6/11/05, Jean-Pierre Denis <jp@webglobe.ca> wrote:
    > Hi,
    >
    >
    > When running snort and iptables on the same box, which of the 2 act first ?
    >
    > Those it go thru snort and then the iptable rule allow or deny the
    > connection
    > or it's the other way around

    Neither. Snort gets a copy of the packets from the kernel via libpcap
    and it doesn't matter what iptables rules you may have enabled. The
    only thing iptables have to do with snort is if you use the inline
    mode (make snort an IPS) and rules that effects Snort's reporting
    modules (database access etc).

    Best regards
     Michael Boman

    -- 
    A: Maybe because some people are too annoyed by top-posting.
    Q: Why do I not get an answer to my question(s)?
    A: Because it messes up the order in which people normally read text.
    Q: Why is top-posting such a bad thing?
    --------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from 
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    --------------------------------------------------------------------------
    

  • Next message: David Kee: "RE: on NIDS/NIPS tuning"

    Relevant Pages

    • Re: Snort & iptables on the same box
      ... > Those it go thru snort and then the iptable rule allow or deny the ... IDS mode, it sees the packets at the same time as Netfilter ...
      (Focus-IDS)
    • slowing down the spread of worms
      ... Is anyone else using the "flexible response" feature of snort to slow ... I'm currently running snort against a mirror of all the traffic for two ... HTTP request sent, awaiting response... ... Read error (Connection reset by peer) in headers. ...
      (Incidents)
    • Re: FW: badnwidth monitor
      ... Well snort will indeed dump more than enough information, ... > person which is hogging the bandwidth.You can ... > Else you can put a bandwidth managing rule on the router. ... >>type, but frankly, my DSL connection at home is more ...
      (Security-Basics)
    • Re: how...
      ... I have a standalone machine with the cable Internet connection. ... running shorewall and I read a little about Snort. ... It is too paranoid to ...
      (alt.linux)
    • Re: What is going on with my Dialup?
      ... have just talked to the ISP hardware and then dropped into a passive mode ... with an occasional keep alive blip. ... Usually you'll have a p2p connection, so you don't get other packets ... Snort is an ids an sniffer like tcpdump, wireshark etc. is what you are ...
      (comp.os.linux.networking)