[Snort-users] snort inline mode is not working with iptables

Russ Combs rcombs at ...1935...
Sat Aug 7 20:48:32 EDT 2010


On Sat, Aug 7, 2010 at 4:52 PM, Jason Brvenik
<jason.brvenik at ...1935...>wrote:

> Comment out all of the include lines in snort.conf, startup should indicate
> 0 rules loaded.
>
In fact, try creating an empty conf and using that.  Then add just the
alert.

Referring to your original setup, examine the packet log and ensure that you
have all the echo responses (you were in the output chain).

If that looks good run tcpdump on your ping machine and see what, if
anything, is coming back.

>  On Aug 7, 2010 5:21 PM, "Wael" <netchildccie at ...125...> wrote:
>
> Hello Jason,
>
> If I did not use iptables -j QUEUE; the ping is working.
>
> How Can I run snort with _NO_rule ?!
>
> Regards,
> Wael,
>
>
> On 8/7/10 9:32 PM, "Jason Brvenik" <jasonb at ...1935...> wrote:
>
> >I would suggest a ground up app...
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20100807/ab1109b6/attachment.html>


More information about the Snort-users mailing list