ng the box as well as do the IPS work.

Date: Sun, 24 Aug 2014 14:00:20 +0200
Subject: Re: [Snort-users] Snort inline mode problem

From: demonsdebason at ...11827...
To: snort at ...15979...

The same behavior when running with 'eth1:eth2'.

Yeah, the interfaces are in promiscuous, silly me.
Any ideas?

On Sun, Aug 24, 2014 at 7:34 AM, Y M wrote:

Date: Sun, 24 Aug 2014 05:02:13 +0200
From: demonsdebason at ...11827...
To: snort-users at

Subject: [Snort-users] Snort inline mode problem

Hi all.
I've been working on my Snort IPS for some time now.
Noticed that 'drop' rules are working half-way, I have set the test rule to
 drop ICMP coming to the sensor from local machine:

drop icmp any -> any (msg: "Test rule"; sid:110011;)

Alerts get logged and can view them via BASE, but when I ping from .2 to .1
 I get this:
PING ( 56(84) bytes of data.

64 bytes from : icmp_seq=1 ttl=64 time=0.216 ms
From icmp_seq=1 Destination Port Unreachable

64 bytes from : icmp_seq=3D2 ttl=3D64 time=3D0.269 ms

>From icmp_seq=3D2 Destination Port Unreachable
64 bytes from : icmp_seq=3D3 ttl=3D64 time=3D0.221 ms

So some of them are getting 'blocked'.

When I shutdown Snort I's all fine:
64 bytes from : icmp_seq=3D8 ttl=3D64 time=3D0.226 ms

64 bytes from
 : icmp_seq=3D9 ttl=3D64 time=3D0.201 ms

64 bytes from : icmp_seq=3D10 ttl=3D64 time=3D0.253 ms
64 bytes from

 : icmp_seq=3D11 ttl=3D64 time=3D0.204 ms

Here is my info:

   ,,_     -*> Snort! <*-
  o"  )~   Version GRE (Build 77)
   ''''    By Martin Roesch & The Snort Team:

           Copyright (C) 2014 Cisco and/or its affiliates. All rights reserved.
           Copyright (C) 1998-2013 Sourcefire, Inc., et al.
           Using libpcap version 1.4.0
           Using PCRE version: 7.8 2008-09-05

           Using ZLIB version: 1.2.3
 41104  4.6  2.0 1675528 1342832 ?     Ssl  04:48   0:00 /usr/sbin/snort
 -D -i eth1::eth2 -u snort -g snort -c /etc/snort/snort.conf -Q
--daq-mode inline -k none

# Looks like you have double colons "eth1::eth2", as opposed to one colon "=
eth1:eth2". Not sure if the double colons are causing the partial drops.

snort --daq-list
Available DAQ modules:
pcap(v3): readback live multi unpriv
ipfw(v3): live inline multi unpriv
dump(v2): readback live inline multi unpriv

afpacket(v5): live inline multi unpriv

config policy_mode:inline
config daq: afpacket
config daq_dir: /usr/lib64/daq
config daq_mode: inline

config daq_var: buffer_size_mb=1024

I've tried dropping all the ICMPs in the iptables, results are as expected,
 but Snort still logs the alerts.
Do you have any idea what is the issue here?

# Does Snort log the requests or replies or both? I would image if the NIC =
is promiscuous, then it would still see the requests.=20

