Facing an issue with Snort
PS:Cross posted in different forums for quick response
Hi all,
recently we installed snort with —enable-inline option and we are able to queue all the 80 port traffic
We have iptables with ip_queue option as mention in snort
documentation
Here are some of my queries
1)How snort will take packets from the queue(Do we have to configure
snort to take packets from ip queue)
2)Ok all 80 port traffic is taken by snort for analyzing, how snort
will pass the genuine packets which passed the test?(Do we have to
create any rule other then pass rule in snort?)
3)What is the difference between snort with —enable-inline and
snort_inline packages?
4)Where can we use rate_filter, i did not find much documentation on
this.. any one used rate_filter in your configuration? please share
it. Where we have to mention rate_filter? do we have to mention in any
configuration file? if yes what is the configuration file?
Thanks in advance to you all.
__________________
Thanks,
Surendra Kumar Anne
Ubuntu: Simple, Stylish and Striking..!
Linux: Fast, friendly, flexible and .... free!
Support Open source.
|