[Snort-users] Newbie question

Potts, Ross A. RPOTTS at ...5660...
Wed Apr 23 04:34:45 EDT 2003


This is why I love this list.  People answering the way Erick did:  He
answered the question, then politely guideed Chris to the archives.

Thanks, Erick!

-----Original Message-----
From: Erick Mechler [mailto:emechler at ...7719...]
Sent: Monday, April 21, 2003 3:54 PM
To: Chris
Cc: snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] Newbie question


:: I am now to IDS and Snort and have a question.  Does having iptable rules
:: setup on the machine affect it in any way?  Oh, it will be behind our
:: firewall.

Chris, if you have firewall software installed on the same system as your 
IDS, then the FW won't affect what your IDS can see.  Snort uses libpcap, 
which is lower on the TCP stack than your FW, so it will see packets before 
they get dropped.

Also, please be sure to check the FAQs and the mailing list archives for
information before posting to the list in the future.  This question has
been answered a few times already in the past.

Cheers - Erick


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users




More information about the Snort-users mailing list