You have snort and ipchains now it would be great if
you incorporated the kernel bridge patches so I can
transparently drop my sniffer/filter onto the network.
examples...
http://ac2i.tzo.com/bridge_filter/
http://lrp.plain.co.nz/tarballs/bridgex_030.tar.gz
summary
this type of configuration uses the built in bridging
functionality of the 2.2.x kernel combined with the
ipchains filtering via a kernel patch. On top of this
you can run snort and guardian to enforce policy
without having to change existing LAN configuration.
Logged In: NO
Yeah this would be a plus if you could add this..
I have been trying the create a bridging kernel to load on a
trinux img, but i'm having very little luck.
More help links:
http://bridge.sourceforge.net/
Keep up the good work.
Chris
Logged In: NO
Any luck with this?