Re: Snort & iptables on the same box

From: snort user (snort.user_at_gmail.com)
Date: 06/14/05

  • Next message: M. Dodge Mumford: "Re: Vulnerability & Exploit Signatures"
    Date: Mon, 13 Jun 2005 18:25:04 -0400
    To: Jean-Pierre Denis <jp@webglobe.ca>
    
    

    Iptables has a bunch of rules
    one of them will say 'forward to QUEUE'
    Snort picks up from this QUEUE and marks it PASS or BLOCK
    Iptables actually drops on that decision
    Other IPtables rules are not affected

    On 6/10/05, Jean-Pierre Denis <jp@webglobe.ca> wrote:
    > Hi,
    >
    >
    > When running snort and iptables on the same box, which of the 2 act first ?
    >
    > Those it go thru snort and then the iptable rule allow or deny the
    > connection
    > or it's the other way around
    >
    >
    > Merci,
    > JP
    >
    >
    > -----------------------------------------
    > WebMail Powered by WebGlobe.
    > http://www.webglobe.ca
    >
    >
    > --------------------------------------------------------------------------
    > Test Your IDS
    >
    > Is your IDS deployed correctly?
    > Find out quickly and easily by testing it with real-world attacks from
    > CORE IMPACT.
    > Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    > to learn more.
    > --------------------------------------------------------------------------
    >
    >

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: M. Dodge Mumford: "Re: Vulnerability & Exploit Signatures"

    Relevant Pages

    • Re: Snort & iptables on the same box
      ... snort rely's on the QUEUE target in iptables to receive its data. ... > Find out quickly and easily by testing it with real-world attacks from ... > CORE IMPACT. ...
      (Focus-IDS)
    • Re: Snort inline and iptables
      ... 1- can i use snort inline+iptables in router mode under linux? ... Subject: Snort inline and iptables ... > with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)
    • Re: newbie needs help with iptables basics (please)
      ... >I have RTFM (man iptables) and have read several docs off the net and pages ... Implement Multi-Router Traffic Grapher to establish network ... discuss & plan the implementation of Snort 2.0 Intrustion ... Install Snort 2.0 Network-based Intrusion Detection System ...
      (comp.os.linux.security)
    • Re: Snort.org on Fedora
      ... > logcheck) that is being maintained and doesn't have licensing issues when I ... but Snort works wonderfully with FC:) ... only snort works well with iptables with the inline patch. ...
      (Fedora)
    • Soho firewall - OpenWRT -WhiteRussian Question
      ... Iptables and snort will be configured per the clients requirements. ... log files will be sent to a syslog server. ... Cureently I only have the virus and malware rules enabled on snort, and the basic config for iptables. ...
      (Security-Basics)