Snort and packet filter question

Gustaf Florén via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <CADkpq3saYXGN4G5D9J0ExeOehdLASXBhSUHQ7sJg40RSKwtHUQ@mail.gmail.com>
Hello!

If I want to filter both incoming and outgoing traffic on a freebsd gateway
using ipfw how do i set up the rules in pf.conf?? I am thinking of using
following rules below and wonder if that "keep state" action in the rules
means that incoming traffic also will be "filtered"  through snort on port
9000???

pass out on eth0 divert-packet port 9000 keep state
pass out on eth1 divert-packet port 9000 keep state

Have I written the rules correctly??

/Gustaf

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.