[Oisf-users] PF_RING, packets and IPS

Will Metcalf william.metcalf at gmail.com
Wed Nov 10 14:58:45 UTC 2010


Luca recently added the ability to perform packet filtering to pf_ring but we have not yet added support.  The transparent setting has to do with the way packets are delivered via options like pf_ring aware nic drivers not IPS vs IDS mode.  There is a detailed description of the various options on the pf_ring website.

Regards,

Will



On Nov 10, 2010, at 8:49 AM, Viacheslav Biriukov <v.v.biriukov at gmail.com> wrote:

> Hello!
> Plz explain to me the path of packets using pf_ring (transparent_mode
> = 0 and transparent_mode = 1) with mode IPS.
> How packets go through netfilter and what the best way to drop packets
> and ban src ip of attakers.
> Have u any diagrams or best practices?
> -- 
> Viacheslav Sov1et Biriukov
> http://openstar.com.ua
> _______________________________________________
> Oisf-users mailing list
> Oisf-users at openinfosecfoundation.org
> http://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users



More information about the Oisf-users mailing list