Where to deploy snort in inline mode??

This is a discussion on Where to deploy snort in inline mode?? within the Snort forums, part of the System Security and Security Related category; I want to only use snort in inline mode that detects portscans by nmap. I have a firewall that drops ...


Go Back   Usenet Forums > System Security and Security Related > Snort

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-25-2007
jeniffer
 
Posts: n/a
Default Where to deploy snort in inline mode??

I want to only use snort in inline mode that detects portscans by
nmap. I have a firewall that drops all packets that dont match its
rules.Where do I place snort? Please help me out.

If I place snort after the firewall ( I mean that there would be a
rule in INPUT chain in iptables to QUEUE packets to userspace) , then
most of the packets will already be dropped, so snort wont get enough
packets to detect that a portscan is taking place. If I place snort in
PREROUTING chain ( the first chain to hit for inbound packets) , till
snort detects an attack , it would pass NF_ACCEPT verdict for all
packets in userspace (See inline.c file) and so no packets would pass
to the firewall now.They would just be accepted and not return to
kernel space to match other firewall rules.I cannot pass IPT_CONTINUE
target in userspace :
http://lists.netfilter.org/pipermail...ay/019722.html

What do I do? Please Please help me out

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:42 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0