From: Will M. <wil...@gm...> - 2004-11-16 00:07:59
|
List, Not sure why this is happening yet, but it appears as if running a 2.6 kernel and filtering on local traffic in the INPUT/OUTPUT chains, snort_inline/snort doesn't properly calculate the checksum of the INBOUND/OUTBOUND packets and they are dropped. If you are experiencing this problem please change the following line in your snort_inline.conf file. config checksum_mode: all config checksum_mode: none Regards, Will |