[Snort-users] Compiling snort for CheckPoint Firewall-1 support

Frank Knobbe frank at ...9761...
Thu May 11 12:31:01 EDT 2006

On Thu, 2006-05-11 at 17:19 +0200, carlopmart wrote:
>   i would like to test snort 2.4.4 release with CheckPoint fw-1
> (NGR55 
> and NGX) and in-line (snort-inline.sf.net) support. I have used
> snortsam 
> last months, but I need a real IPS now thath sends commands to my 
> firewalls and blocks traffic. How can I compile snort for fw1
> support???

Uhm... that *IS* what Snortsam does. It sends commands to your firewall
to block traffic.

On Thu, 2006-05-11 at 14:29 -0400, Paul Melson wrote: 
> You can't build Snort with FW-1 specific support like you can with
> RealSecure or other commercial products that have OPSEC(tm) support.

Snortsam provides that OPSEC support, but not straight from Snort. It is
interfaced by Snortsam (Snort->Snortsam->FW-1).


It is said that the Internet is a public utility. As such, it is best
compared to a sewer. A big, fat pipe with a bunch of crap sloshing
against your ports.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 187 bytes
Desc: This is a digitally signed message part
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20060511/68d3afbf/attachment.sig>

More information about the Snort-users mailing list