From mboxrd@z Thu Jan 1 00:00:00 1970 From: Martijn Lievaart Subject: Re: Iptables rule on span traffic Date: Mon, 23 Apr 2007 07:44:43 +0200 Message-ID: <462C47CB.8030806@rtij.nl> References: <1177172639.25008.1.camel@anduril.intranet.cartel-securite.net> <462A8014.6000105@plouf.fr.eu.org> <462C4337.1060508@rtij.nl> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-bounces@lists.netfilter.org Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii"; format="flowed" To: "Krishnamoorthy (Siva) Sivakumar" Cc: netfilter@lists.netfilter.org, Pascal Hambourg Krishnamoorthy (Siva) Sivakumar wrote: > You could try to turn on forwarding and block all traffic that makes it > through the snort rules. > > HTH, > M4 > > [Siva:] > Can you explain in more detail (sorry I am a novice)? How do you turn on forwarding? Does this require the iptables machine to be inline (in addition to a regular firewall/router that does the actual forwarding)? > > http://www.google.nl/search?q=linux+forwarding :-) HTH, M4