Freebsd & snort inline



Hi,

I want to use snort-inline on my freebsd 6.1 box with ipfw, bridge and mysql. I have it configured the right way. But the only alerts/drops i get are the following:

(snort decoder) Bad Traffic Loopback IP
(snort decoder) Bad Traffic Same Src/Dst IP

I heard that the freebsd divert do not work with the bridge? I hope someone figured it out.


Thanks in advantage

Ruurd

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • Re: Freebsd & snort inline
    ... I want to use snort-inline on my freebsd 6.1 box with ipfw, bridge and mysql. ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic Excellence in Information Security. ... describe your configs and task. ...
    (Security-Basics)
  • Re: Re: Freebsd & snort inline
    ... I'm not exactly sure but I don't think you will have any luck getting the bridge going with snort inline. ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic Excellence ...
    (Security-Basics)
  • Re: Wireless Bridge in FreeBSD 6.1
    ... >> I'm having trouble to bridge two wireless card which is Atheros AR5213A ... >> FreeBSD 6.1. ... > and friends) if you are using infrastructure mode and a-hoc mode is ...
    (freebsd-questions)
  • Re: Kernel Development
    ... together (eg. be able to bridge a ng_fec virtual interface.. ... Subject: Kernel Development ... I am looking to get involved in FreeBSD system development and was ... To unsubscribe, ...
    (freebsd-hackers)
  • Re: Bridging only 2 interfaces???
    ... Personally IPF is my prefered choice over IPFW, ... I use FreeBSD for all other things too, but think would be kewl to have this ... >> I have set up a bridging firewall that has 3 interfaces. ... Is it possible to set up the machine to bridge just ...
    (FreeBSD-Security)