Re: Inline Mode
Joel Esler via Snort-users <[email protected]> Wed, 24 Apr 2024 14:35:03 -0400
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Much easier said than done. Considering the majority of Snort users are IDS and only are functioning with one network card. > On Apr 19, 2024, at 12:15, Guillaume - Libvert.fr via Snort-users <[email protected]> wrote: > > Right => Snort developers should indeed configure the application to drop bad packets by default > > > >> Le jeu. 18 avr. 2024 à 20:18, Len Dyck via Snort-users <[email protected] <mailto:Le jeu. 18 avr. 2024 %C3%A0 20:18, Len Dyck via Snort-users <<a href=>> a écrit : >>> >>> Hi fellow snorters. I have been unable to find concise instructions on how one would go about setting up a Snort interface to work in inline mode. I have a basic understanding of the pieces, but I get stuck at the SID Management Configuration Lists. The end result that I'm after is to configure all rules that are enabled to be set to drop instead of alert. Appreciate the help. > _______________________________________________ > Snort-users mailing list > [email protected] > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users > > To unsubscribe, send an email to: > [email protected] > > Please visit http://blog.snort.org to stay current on all the latest Snort news! > > Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette