|
From: 吴鲁加 <wu...@gm...> - 2010-10-28 02:06:15
|
In devil-linux default boot.iso, snort can't work as IPS, you need to configure Snort install with: “./configure —enable-inline” , follow this steps: 1. edit build/scripts/snort, add --enable-inline in ./configure. 2. edit build/scripts/iptables, add --enable-libipq -- snort need this lib to check packet in iptables's QUEUE. 3. download Libnet-1.0.2a, copy build/scripts/Libnet and edit it for your need. 4. edit build/Makefile.build, change Libnet to Libnet-1.02a(snort can't work with Libnet > 1.1); 5. edit build/Makefile.build, make sure snort build after iptables,because it need iptables's header and libs. snort: | $(GROUP_23) ; 6. and, because we use old libnet, syslog-ng will report an error, just edit build/script/syslog-ng, set --enable-spoof-source=no; that's it, you can make all to test it, if somebody want to use snort's IPS future, hope it helps. -- wulujia<wu...@un...> Tel:400 1122 918 Web:www.unnoo.com / www.xiaobai.com |