hamed.sheykhlu at gmail
Apr 27, 2012, 10:00 PM
Post #1 of 1
excuse-me, i don't know that it is right location to my question or not.
i recently install snort with pfring module. everything goes well in ids
mode, and traffic clustred to multiple snort instance.
but i want to enable ips mode in snort with pfring. in some websites says
that its possible, but without the solution.
1. pfring how can drop packet? in standard snort ips mode, packets add to
QUEUE and drop with iptables command.
2. is DNA feature essential for IPS mode?
excuse me for my bad English.
hamed.sheykhlu [at] gmail
hamed.sheykhlu [at] sanayco