[Oisf-users] Fwd: IPS

Will Metcalf william.metcalf at gmail.com
Tue Jun 15 14:14:31 UTC 2010

> I didn't inderstand wht is "fast_pattern",
If you are interested in an in-depth explanation of what this keyword
does I suggest you read the snort manual.  The short version is that
you tell the engine(s) that a match is more unique so that it favors
it over longer more generic matches.

> is using old rulesets means tht snort is better than Suricata ?
heh. I'm a bit biased I think,  why don't you tell us how your
experience went as a user of both.

> wht is the better way, to save iptables config, and how can we run suricata
> auotomaticlly ??

Take a look at scripts in your /etc/init.d/ or /etc/rc.d/ directory
for an example of how to handle these things. This link may help ;-)




