Re: Snort & iptables on the same box

From: Michael Boman (michael.boman_at_gmail.com)
Date: 06/15/05

  • Next message: dgr8hunt: "Re: Vulnerability & Exploit Signatures"
    Date: Wed, 15 Jun 2005 06:43:53 +0800
    To: focus-ids@securityfocus.com
    
    

    On 6/14/05, Will Metcalf <william.metcalf@gmail.com> wrote:
    > snort rely's on the QUEUE target in iptables to receive its data.

    Only in inline (IPS) mode. As an IDS it uses libpcap to recieve data
    and doesn't care what firewall rules you have in place.

    Best regards
     Michael Boman

    -- 
    A: Maybe because some people are too annoyed by top-posting.
    Q: Why do I not get an answer to my question(s)?
    A: Because it messes up the order in which people normally read text.
    Q: Why is top-posting such a bad thing?
    --------------------------------------------------------------------------
    Test Your IDS
    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from 
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708 
    to learn more.
    --------------------------------------------------------------------------
    

  • Next message: dgr8hunt: "Re: Vulnerability & Exploit Signatures"

    Relevant Pages

    • Re: Terminology: Inline IDS, IPS and Application Layer Firewall
      ... In fact, I would say that in most cases, packets are _bridged_ across them. ... You simply stick it inline and it bridges the traffic while sniping/blocking "bad" traffic. ... As to the differences between the 3 terms you mention, let's first make the assumption that IPS refers to an inline IPS. ... Inline IDS could simply refer to an IDS system that gets it's traffic by sitting inline. ...
      (Focus-IDS)
    • Re: Wishlist for IPS Products
      ... Most of the fetaures are common across IDS, ... signature have to be robust and accurate in all three cases. ... IPS products give provision for ... Inline products give quite a bit of advantage ...
      (Focus-IDS)
    • RE: amount of alarms generated by IDS
      ... You're talking about inline IDS and IPS. ... If an IDS doesn't have the ability to drop packets, ...
      (Focus-IDS)
    • RE: Cisco IDS 4250 vs Sourcefire IS3000 + RNA Sensor
      ... Since when has an inline IDS become an IPS, ... protection against the worm that got straight through ...
      (Focus-IDS)
    • RE: amount of alarms generated by IDS
      ... Inline IDS exists, it's just what you call your IPS ... will the IPS vendors usurp the firewall vendors or will the firewall ...
      (Focus-IDS)