Re: Problems with snort 2.9 nfq inline

"esaki.atsushi" <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CAJkw7pru1vMaum=+j-_755t2ZSOgoyKYkjaRCtVtVJWiFeqsUQ@mail.gmail.com>
Subsequent investigation revealed a parameter that allows us to adjust
the amount of time Snort keeps dropping packets.

  preprocessor stream5_global: \
    max_active_responses <max_rsp>, \
    min_response_seconds <min_sec>.

It seems that if I set max_active_responses to 5 and
min_response_seconds to about 300, I can exceed net.ipv4.tcp_retries2
(default 15) and time out the connection.
This may not be the correct way to use Snort to block packets, but it
seems to meet the requirements.

If anyone have any notes or advice, please let me know.

Best regards,
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.