par Vehrsey » 26 Mars 2012 21:34
The option "enable-inline" doesn't exist with snort 2.9.x. It's compiled by default.
Snort works with DAQ modules (inline mode):
There are several choices DAQ modules : NFQ, IPQ, AFPACKET, ...
In mode inline (mode NFQ), packages "libnetfilter_queue" and "libnetlink" are needed before for exemple.
You can switch from passive to inline with the option -Q. Exemple: ./snort -c /directory/snort.conf -Q --daq nfq
Nevertheless each one has advantages and defects. With mode NFQ or IPQ, this modules can not run unprivileged so ./snort -u -g will produce a warning
and won't change user or group.
With AFPACKET mode it takes more memory and works with one or more interface pairs (eth0:eth1) or (eth0:eth1::eth2:eth3).