Snort_inline
snort_inline is basically a modified version of Snort
that accepts packets from iptables and IPFW via libipq instead
of libpcap. It interacts with the firewall by reading packets, and
either dropping, rejecting, altering, or passing them onto your network
based on your snort rules.
It uses new rule types to tell iptables if the packet should be dropped
or allowed to pass based on the Snort
rules.
snort_inline supports all options currently configured with
snort, but with the additional functionality of processing packets from
Linux IPTables Queues.
Features include:
- See Snort
page for details
Return
to Security Home Page
Last Updated Sunday, May 04 2008 @ 05:20 AM EDT |