[Oisf-users] Inline Mode

Brant Wells bwells at tfc.edu
Fri Jan 22 22:43:28 UTC 2010


Hi All,

I was just curious as to whether or not Suricata runs in Inline mode as an IPS now?

If so, the -q parameter asks for a qid - is this an arbitrary number, or does it match up with something from say... iptables?

To that end.... When I run Snort (in inline mode), I have to use

iptables -I FORWARD -i br0 -p all -j QUEUE

Do I need to run that for Suricata in inline mode as well?

Thanks!
~Brant

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20100122/fbdae9c4/attachment-0002.html>


More information about the Oisf-users mailing list