From: [Minag] <gve...@mi...> - 2005-01-04 22:41:58
|
William, > Ummmmm do you really want http_inspect to drop packets?=20 Really no. I was worried because I have many fp's from this preprocessor = in the IDS (only Snort, not Inline) and I will setup Snort-Inline on the Fir= ewall and I dont want to drop this fp's I have=20 > experienced a large number of fp's from this preproc. But the answer=20 > is yes it can, you have to Call InlineDrop() from inline.h for=20 > Packet *p where the condition you want to check against is met.=20 Thanks for the reference. > Will this ever be a standard for snort_inline probably not. I hope I=20 > didn't sound to short with you, or anybody on the list. This is day=20 > 5 without a cigarette and after 10 years of smoking(yes I'm only 24)=20 > I'm finding that I'm a tad bit irritable these days. >=20 > Regards, >=20 Thank you again, take care of your health. Regards, Geffrey > Will > "Geffrey Vel=E1squez [Minag]" <gve...@mi...> >=20 > "Geffrey Vel=E1squez [Minag]" <gve...@mi...>=20 > Sent by: sno...@li... >=20 > 01/04/2005 04:10 PM >=20 > To =20 > sno...@li... >=20 > cc >=20 > Subject =20 > [Snort-inline-users] preprocessor: http_inspect could drop packets? >=20 > Hi friends, >=20 > I want to know if the http_inspect could drop packets, and in=20 > general any preprocessor. >=20 > Regards, > Geffrey Velasquez >=20 > ------------------------------------------------------- > The SF.Net email is sponsored by: Beat the post-holiday blues > Get a FREE limited edition SourceForge.net t-shirt from ThinkGeek. > It's fun and FREE -- well, almost....http://www.thinkgeek.com/sfshirt > _______________________________________________ > Snort-inline-users mailing list > Sno...@li... > https://lists.sourceforge.net/lists/listinfo/snort-inline-users ------- End of Original Message ------- |