Re: Snort inline and iptables

From: Terry Vernon (tvernon24_at_comcast.net)
Date: 08/22/05

  • Next message: Michal Melewski: "Re: Snort inline and iptables"
    Date: Mon, 22 Aug 2005 05:52:33 -0500
    To: afshinlamei@gmail.com
    
    

    1- Yes
    2- Depends on the horsepower you are using. p2 233 causes some lag in
    the network with this setup.

    afshinlamei@gmail.com wrote:

    >Dear all,
    >1- can i use snort inline+iptables in router (no bridge) mode under linux?
    >2- what's the performance issuses when using snort inline + flexresponse mode?
    >thanks
    >afshin
    >
    >------------------------------------------------------------------------
    >Test Your IDS
    >
    >Is your IDS deployed correctly?
    >Find out quickly and easily by testing it
    >with real-world attacks from CORE IMPACT.
    >Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    >to learn more.
    >------------------------------------------------------------------------
    >
    >
    >
    >

    ------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it
    with real-world attacks from CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    ------------------------------------------------------------------------


  • Next message: Michal Melewski: "Re: Snort inline and iptables"

    Relevant Pages

    • Re: IDS Evaluation
      ... vulnerability scanning). ... We actually include a limited license copy of Core Impact with our ... Evaluation boxes that we ship so people can easily evaluate our IPS ... >> about the accuracy of the ids. ...
      (Focus-IDS)
    • Re: RE: IDS testing tools
      ... Nessus is a bad choice to test IDS as it is a vulnerability scanner. ... >Find out quickly and easily by testing it with real-world attacks from CORE ... >with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)
    • Re: Host Based IDS
      ... Assunto: RE: Host Based IDS ... Anitian Enterprise Security ... with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)
    • RE: IDS
      ... Subject: IDS ... Safe Access that does pretty much what you describe. ... Find out quickly and easily by testing it with real-world attacks from ... with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)
    • RE: IDS event filtering
      ... It is important to avoid tuning out real attacks when they happen by having over-pruned the inside attack tree... ... > ingress - egress firewall rules, IDS configs, or whatever. ... > CORE IMPACT. ... > Find out quickly and easily by testing it with real-world attacks from ...
      (Focus-IDS)