Re: Problem snort
"Al Lewis \(allewi\) via Snort-users" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
I think you are mistaken. Check the DAQ readme file(as shown below).
AFPACKET Module
===============
afpacket functions similar to the pcap DAQ but with better performance:
./snort --daq afpacket -i <device>
[--daq-var buffer_size_mb=<#MB>]
[--daq-var debug]
If you want to run afpacket in inline mode, you must craft the device string as
one or more interface pairs, where each member of a pair is separated by a
single colon and each pair is separated by a double colon like this:
eth0:eth1
or this:
eth0:eth1::eth2:eth3
Albert Lewis
ENGINEER.SOFTWARE ENGINEERING
Cisco Systems Inc.
Email: [email protected]<mailto:[email protected]>
From: Snort-users <[email protected]> on behalf of Dorian ROSSE via Snort-users <[email protected]>
Reply-To: Dorian ROSSE <[email protected]>
Date: Friday, April 8, 2022 at 2:21 PM
To: "[email protected]" <[email protected]>
Subject: [Snort-users] Problem snort
Hello,
Afpacket doesn't support inline if I have the truth about an old e-mail I have readen,
I hope your success,
Regards.
Dorian Rosse.
_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users
To unsubscribe, send an email to:
[email protected]
Please visit http://blog.snort.org to stay current on all the latest Snort news!
Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette