Anyway, got an arch linux server setup with iptables and snort, snort is all taken care of and is working via nfq and afpacket DAQs in inline mode...
What I'd like to do, however, is use iptables to block some IPs and ports, before allowing the rest of the data to pass on through to snort and then out another ethernet interface to the server(s).
Only problem is, it requires NAT, and me, iptables and the FORWARD/NAT chain don't seem to get on, I've no idea how to go about doing it
So I'm quite literally stuck and haven't got a CLUE how to do this, any ideas?






