[Snort-users] Block packets using snort with pf_ring

Lavanya Kumar lavanyakumar84 at ...11827...
Mon Sep 28 02:49:22 EDT 2015


i am running snort-2.9.7.3 with pfring-6.0.3 ,libpcap-1.6.2 and i want to
block the packets by writing snort rules.But i am not able to drop packets
but they are logging the alerts.
please help me with the snort command and suggestions.

presently i am running snort with the following command  :

/usr/local/snort -Q --process-all-events -c /etc/snort.conf -d --daq pfring
--daq-dir=/usr/local/lib/daq/ -l /usr/logs -i eth0:eth1

Thanks
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20150928/b01f4fcd/attachment.html>


More information about the Snort-users mailing list