[Oisf-users] suricata af-packet and packet forwarding

Eric Leblond eric at regit.org
Tue Jun 11 06:15:42 UTC 2013


Hello,

Le mardi 11 juin 2013 à 07:39 +0200, Heřbolt, Lukáš a écrit :
> Hi all,
> I have a question about suricata in AF-PACKET ips mode.
> 
> 
> Is it posible to use this mode on router where interface traffic
> between eth0 and eth1 are fowarded (NATed). 

No, it acts as a transparent layer 2 bridge, so no transformation are
made on the datagram.

BR,

> 
> 
> Thank you
> 
> Lukáš Heřbolt
> Linux Administrátor
> 
> ETNETERA | smart e-business
> 
> [a] Milady Horákové 108, 160 00 Praha 6
> [m] +420 725 267 158 [i] www.etnetera.cz 
> ~
> [www.ifortuna.cz  | www.o2.cz    | www.datart.cz ]
> [www.skodaplus.cz | www.nivea.cz | www.allianz.cz]
> 
> Created by ETNETERA | Powered by jNetPublish
> _______________________________________________
> Suricata IDS Users mailing list: oisf-users at openinfosecfoundation.org
> Site: http://suricata-ids.org | Support: http://suricata-ids.org/support/
> List: https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users
> OISF: http://www.openinfosecfoundation.org/

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 190 bytes
Desc: This is a digitally signed message part
URL: <http://lists.openinfosecfoundation.org/pipermail/oisf-users/attachments/20130611/421ec24c/attachment.sig>


More information about the Oisf-users mailing list