Is it possible to run Suricata IPS mode with PF_RING?
Jing-Wei Su <[email protected]> Mon, 20 May 2019 23:51:00 +0800
| Newsgroups | gmane.linux.ntop.general |
|---|---|
| Message-ID | <CAFKS8hXVP_Du6aUeG2Rb_VOFg3S_xK9jsZrcE4RL8JrsUbn_sQ@mail.gmail.com> |
--===============2708023533545948100== Content-Type: multipart/alternative; boundary="0000000000009dc1b8058953b300" --0000000000009dc1b8058953b300 Content-Type: text/plain; charset="UTF-8" Hello, I have tried Suricata with NFQUEUE to achive IPS mode. I have one question is that s it possible to run Suricata IPS mode with PF_RING ? If not, why can we do that? Or, is PF_RING only suitable for IDS mode? Thanks, Derek --0000000000009dc1b8058953b300 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Hello,<div><br></div><div>I have tried Suricata with NFQUE= UE to achive IPS mode.</div><div>I have one question is that=C2=A0s it poss= ible to run Suricata IPS mode with PF_RING ?</div><div>If not, why can we d= o that?</div><div>Or, is PF_RING only suitable for IDS mode?</div><div><br>= </div><div>Thanks,</div><div>Derek</div></div> --0000000000009dc1b8058953b300-- --===============2708023533545948100== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Ntop mailing list [email protected] http://listgateway.unipi.it/mailman/listinfo/ntop --===============2708023533545948100==--