From: Brian J. <te...@ja...> - 2006-05-26 13:57:37
|
Ok, I'll see what happens if I migrate to 2.4.4. This will take some time as snort_inline is on a firewall stripped of compilers and other useful gadgets and the build box has had to change to a different distro.... Also I should be picking up the keys to my new house today(No sign of them yet at 15:00hrs!). I think I'm in for a chaotic time! regards, Brian -----Original Message----- From: sno...@li... [mailto:sno...@li...]On Behalf Of Will Metcalf Sent: 26 May 2006 13:30 To: te...@ja... Cc: sno...@li... Subject: Re: [Snort-inline-users] Reloading rules I think the normal snort had some problems with signal handling. Is there a reason why have not gone to 2.4.4? Setting enforce_state will only make the problem worse, as it will kill all established tcp connections when the process restarts. Regards, Will |