[Snort-users] Block

Matt Kettler mkettler at ...4108...
Tue Feb 17 08:04:08 EST 2004


At 10:48 PM 2/16/2004, Brian wrote:
> > 2) snort-inline
> >         - linux kernel specific at the moment, but does true kernel-level
> > firewall interaction as packets arrive.
>
>IIRC, snort-inline works on FreeBSD as well, using divert sockets.

Brian, I don't think that the FreeBSD code is considered stable yet. I 
could be wrong, but there's nothing on the project page or mailing list to 
indicate otherwise.

Looking at their mailing list archives they got their first user to test it 
on 1/12/04.

So, while the code exists, and it should work, it's still quite new and 
hasn't had much more than a month of testing.

I'd give the FreeBSD version a try on a test box, but I don't think I'd 
quite consider it for a production system.. at least not yet.. 





More information about the Snort-users mailing list