[Snort-users] Question on snort redirecting
mkettler at ...4108...
Wed Feb 4 08:00:40 EST 2004
At 04:47 AM 2/4/2004, =?big5?q?WAN=20FAT=20WU?= wrote:
> Can snort redirect packet or traffic to other
Snort? No.... Snort is a pcap-layer IDS.. as such, it gets a copy of the
packet more-or-less at the same time as the kernel firewall does. ie: both
events happen in parallel.. packets don't go through snort, they get copied
to it as they come in off the ethernet layer.
The snort-inline package might do what you need, however I've never tried
it as it's Linux/IPTables specific (my snort box is *BSD based)
More information about the Snort-users