[Oisf-users] OT: Filtering police for ingress and egress traffic

C. L. Martinez carlopmart at gmail.com
Thu Sep 19 07:53:51 UTC 2013

Hi all,

 I have two suricata sensors "connected" to a one SPAN port, but I
have a problems with duplicate packets like Richard Bejtlich explains
in this post:


 Somebody knows if it possible to establish some type of filtering
police to discriminate ingress and egress traffic using linux network

 I have found some options using "tc" commands but I don't know if
this can works ... Any example??


More information about the Oisf-users mailing list