Bluehost.com Web Hosting $6.95

Re: [Snort-users] snort inline behavior

This is a discussion on Re: [Snort-users] snort inline behavior within the Snort forums, part of the System Security and Security Related category; > If you add a QUEUE rule to iptables, you have to make sure that a process > is actually ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 11-26-2003
/dev/null
 
Posts: n/a
Default Re: [Snort-users] snort inline behavior

> If you add a QUEUE rule to iptables, you have to make sure that a process
> is actually listening to the ip_queue. Otherwise netfilter actually waits
> until a process picks up the packets.


Woah. What happens when snort_inline dies or maybe when we need to
stop/start snort_inline? Ooops.

I'm guessing there is a "dummy" app that you can set up to always listen to
the queue so this problem doesn't happen? If not I need to write one.

> There is another issue. As soon as snort_inline has decided whether to

drop
> or accept a packet, the following iptables rules are not being used

anymore.
> The decision whether to accept or drop a packet is solely made in snort

then.
> This way you can have the problem that your packet filter ruleset becomes

ineffective.

Yeah, well by the time I've decided to ACCEPT, it's passed through all the
rules it's going to pass through and it really needs to be accepted (minus
the scrutiny of snort_inline).

So I take it if whatever apps are listening to QUEUE don't DROP it, it's
ACCEPTed, eh?

Thanks!



-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
Does SourceForge.net help you be more productive? Does it
help you create better code? SHARE THE LOVE, and help us help
YOU! Click Here: http://sourceforge.net/donate/
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 11:51 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0