[Snort-users] snort and firewall all in one machine

Peggy Kam ppkam at ...11126...
Thu May 13 06:53:03 EDT 2004


I am currently running the firewall and snort within the same machine; 
and snort is having its detections before firewall blocks the packets.  
I would like to use snort to test if my firewall actually blocks the 
packets launched by attackers.  Would anyone give me some advice on how 
I could configure IDS to do its detections after the firewall blocks the 
packets by its rules?

Thanks in advance,

More information about the Snort-users mailing list