Recommended Posts

I ditched pfSense, not sure why but it was just rubbish.

Anyway, got an arch linux server setup with iptables and snort, snort is all taken care of and is working via nfq and afpacket DAQs in inline mode...

What I'd like to do, however, is use iptables to block some IPs and ports, before allowing the rest of the data to pass on through to snort and then out another ethernet interface to the server(s).

Only problem is, it requires NAT, and me, iptables and the FORWARD/NAT chain don't seem to get on, I've no idea how to go about doing it :(. Looked around the net and came across various examples, but they're all rubbish quite frankly and require you have internal IPs and specify them directly, etc. whereas I want this server to just drop bad traffic and forward it out another interface, so the servers can still use public IPs.

So I'm quite literally stuck and haven't got a CLUE how to do this, any ideas?

Link to comment
https://www.neowin.net/forum/topic/1075113-iptables-and-snort/
Share on other sites

This topic is now closed to further replies.
  • Posts

  • Recent Achievements

    • One Month Later
      Sopa flores earned a badge
      One Month Later
    • First Post
      StaticMatrix earned a badge
      First Post
    • Week One Done
      StaticMatrix earned a badge
      Week One Done
    • Rookie
      lamborghiniv10 went up a rank
      Rookie
    • One Month Later
      pinnclepd earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      504
    2. 2
      PsYcHoKiLLa
      207
    3. 3
      +Edouard
      155
    4. 4
      Steven P.
      87
    5. 5
      ATLien_0
      79
  • Tell a friend

    Love Neowin? Tell a friend!