[Snort-users] Question on snort redirecting

Matt Kettler mkettler at ...4108...
Wed Feb 4 08:00:40 EST 2004


At 04:47 AM 2/4/2004, =?big5?q?WAN=20FAT=20WU?= wrote:
>    Can snort redirect packet or traffic to other
>  computer?

Snort? No.... Snort is a pcap-layer IDS.. as such, it gets a copy of the 
packet more-or-less at the same time as the kernel firewall does. ie: both 
events happen in parallel.. packets don't go through snort, they get copied 
to it as they come in off the ethernet layer.

The snort-inline package might do what you need, however I've never tried 
it as it's Linux/IPTables specific (my snort box is *BSD based)





More information about the Snort-users mailing list