Re: [Snort-users] snort + iptables

This is a discussion on Re: [Snort-users] snort + iptables within the Snort forums, part of the System Security and Security Related category; > Hi > I was wondering : > If I put snort on the same machine iptables is running both will ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 11-26-2004
Senthil Prabu.S
 
Posts: n/a
Default Re: [Snort-users] snort + iptables


> Hi
> I was wondering :
> If I put snort on the same machine iptables is running both will catch the
> same packets or frames?
> I think this is a waste of resources, isn't it?
> I know snort_inline accepts only packets from iptables, so that's OK!
> But what about snort? It is still using libpcap to catch the traffic,


Snort operates using libpcap.It analysis everything the network
adapter
driver sees before the network stack munges it. Linux IPTables, do not
prevent
snort from seeing a packet that is present on the network wire. Even if an
inbound
packet is denied by the packet filter,ie by IPTables. Snort will still see
and analyze
the packet if it is listening to that interface. Snort/pcap sees whatever
comes out of
or goes into the network adapter.
The above said holds good for only inbound trafiic.


>how can I make it listen only to the traffic iptables filter?
>

Also Snort cannot look at the outgoing packets that are being
denied by filters,since they will never reach the network adapter.

Hopes this helps....


--
Senthil Prabu.S


Logic is a systematic method of coming to the wrong conclusion with
confidence.
__________________________________________________ _______________





-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://productguide.itmanagersjournal.com/
_______________________________________________
Snort-users mailing list
Snort-users@lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/...fo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.p...st=snort-users
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 03:06 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0