[Snort-users] Snort and APF firewall

Matt Kettler mkettler at ...4108...
Sat Dec 13 12:01:01 EST 2003

At 07:11 PM 12/13/2003, Virgil Iancu wrote:
>I need to know how I could activate alarms from portscan2 preproccesor 
>into a log file suitable for APF firewall.

First, I've never heard of anyone refer to "APF firewall" prior to this 
message. Next time, try to at least include some more detail about what 
exactly you are talking about.

Doing a crude search, APF appears to be "advanced policy firewall", which 
is IPTables based.

If it's just IPTables, use snortsam, or something of the like.


More information about the Snort-users mailing list