<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Compiling Suricata 0.9.0 in Ubuntu Lucid 10.04 in IPS (inline) mode</title>
	<atom:link href="http://www.inliniac.net/blog/2010/05/07/compiling-suricata-0-9-0-in-ubuntu-lucid-10-04-in-ips-inline-mode.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.inliniac.net/blog/2010/05/07/compiling-suricata-0-9-0-in-ubuntu-lucid-10-04-in-ips-inline-mode.html</link>
	<description>Everything inline.</description>
	<lastBuildDate>Mon, 30 Jan 2012 16:49:09 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: jackwssp</title>
		<link>http://www.inliniac.net/blog/2010/05/07/compiling-suricata-0-9-0-in-ubuntu-lucid-10-04-in-ips-inline-mode.html/comment-page-1#comment-21178</link>
		<dc:creator>jackwssp</dc:creator>
		<pubDate>Tue, 22 Jun 2010 18:45:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=360#comment-21178</guid>
		<description># /usr/bin/suricata -c /etc/suricata/suricata.yaml -D -q 0
[6660] 22/6/2010 -- 18:44:16 - (suricata.c:354)  (main) -- This is Suricata version 0.9.1
[6660] 22/6/2010 -- 18:44:16 - (util-cpu.c:167)  (UtilCpuPrintSummary) -- CPUs Summary:
[6660] 22/6/2010 -- 18:44:16 - (util-cpu.c:169)  (UtilCpuPrintSummary) -- CPUs online: 2
[6660] 22/6/2010 -- 18:44:16 - (util-cpu.c:171)  (UtilCpuPrintSummary) -- CPUs configured 2</description>
		<content:encoded><![CDATA[<p># /usr/bin/suricata -c /etc/suricata/suricata.yaml -D -q 0<br />
[6660] 22/6/2010 &#8212; 18:44:16 &#8211; (suricata.c:354)  (main) &#8212; This is Suricata version 0.9.1<br />
[6660] 22/6/2010 &#8212; 18:44:16 &#8211; (util-cpu.c:167)  (UtilCpuPrintSummary) &#8212; CPUs Summary:<br />
[6660] 22/6/2010 &#8212; 18:44:16 &#8211; (util-cpu.c:169)  (UtilCpuPrintSummary) &#8212; CPUs online: 2<br />
[6660] 22/6/2010 &#8212; 18:44:16 &#8211; (util-cpu.c:171)  (UtilCpuPrintSummary) &#8212; CPUs configured 2</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Victor Julien</title>
		<link>http://www.inliniac.net/blog/2010/05/07/compiling-suricata-0-9-0-in-ubuntu-lucid-10-04-in-ips-inline-mode.html/comment-page-1#comment-21150</link>
		<dc:creator>Victor Julien</dc:creator>
		<pubDate>Mon, 21 Jun 2010 07:18:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=360#comment-21150</guid>
		<description>Does Suricata report an error? Start without the -D option to see what it reports.</description>
		<content:encoded><![CDATA[<p>Does Suricata report an error? Start without the -D option to see what it reports.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jackwssp</title>
		<link>http://www.inliniac.net/blog/2010/05/07/compiling-suricata-0-9-0-in-ubuntu-lucid-10-04-in-ips-inline-mode.html/comment-page-1#comment-21111</link>
		<dc:creator>jackwssp</dc:creator>
		<pubDate>Sat, 19 Jun 2010 09:53:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=360#comment-21111</guid>
		<description>Hey, bro, where is my comment?</description>
		<content:encoded><![CDATA[<p>Hey, bro, where is my comment?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jackwssp</title>
		<link>http://www.inliniac.net/blog/2010/05/07/compiling-suricata-0-9-0-in-ubuntu-lucid-10-04-in-ips-inline-mode.html/comment-page-1#comment-21102</link>
		<dc:creator>jackwssp</dc:creator>
		<pubDate>Fri, 18 Jun 2010 19:09:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=360#comment-21102</guid>
		<description>Suricata 0.9.2rc3, compiled like this:
 
CFLAGS=&quot;-O3 -march=i486 -mtune=i686&quot; \
./configure --prefix=/usr --enable-unified-native-timeval --enable-nfqueue --build=i486-Slackware-linux &quot;$@&quot;
make
make install DESTDIR=$TMP

try to configure iptables by this way:

iptables -t mangle -A PREROUTING -j NFQUEUE --queue-num 0
iptables -t mangle -A FORWARD -j NFQUEUE --queue-num 0
iptables -t mangle -A OUTPUT -j NFQUEUE --queue-num 0

do not work :(</description>
		<content:encoded><![CDATA[<p>Suricata 0.9.2rc3, compiled like this:</p>
<p>CFLAGS=&#8221;-O3 -march=i486 -mtune=i686&#8243; \<br />
./configure &#8211;prefix=/usr &#8211;enable-unified-native-timeval &#8211;enable-nfqueue &#8211;build=i486-Slackware-linux &#8220;$@&#8221;<br />
make<br />
make install DESTDIR=$TMP</p>
<p>try to configure iptables by this way:</p>
<p>iptables -t mangle -A PREROUTING -j NFQUEUE &#8211;queue-num 0<br />
iptables -t mangle -A FORWARD -j NFQUEUE &#8211;queue-num 0<br />
iptables -t mangle -A OUTPUT -j NFQUEUE &#8211;queue-num 0</p>
<p>do not work <img src='http://www.inliniac.net/blog/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jackwssp</title>
		<link>http://www.inliniac.net/blog/2010/05/07/compiling-suricata-0-9-0-in-ubuntu-lucid-10-04-in-ips-inline-mode.html/comment-page-1#comment-21101</link>
		<dc:creator>jackwssp</dc:creator>
		<pubDate>Fri, 18 Jun 2010 18:44:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.inliniac.net/blog/?p=360#comment-21101</guid>
		<description>Look, i try this, 

/usr/bin/suricata -c /etc/suricata/suricata.yaml -D -q 0

with this

iptables -t raw -A PREROUTING -j NFQUEUE --queue-num 0
iptables -t raw -A OUTPUT -j NFQUEUE --queue-num 0

and it wantnt work, but snort works well.

For example, this rule doesnt work:
local.rules:
drop tcp any any  any any (msg:&quot;DROP ALL&quot;; content:&quot;google.com&quot;;       sid:3000010;)</description>
		<content:encoded><![CDATA[<p>Look, i try this, </p>
<p>/usr/bin/suricata -c /etc/suricata/suricata.yaml -D -q 0</p>
<p>with this</p>
<p>iptables -t raw -A PREROUTING -j NFQUEUE &#8211;queue-num 0<br />
iptables -t raw -A OUTPUT -j NFQUEUE &#8211;queue-num 0</p>
<p>and it wantnt work, but snort works well.</p>
<p>For example, this rule doesnt work:<br />
local.rules:<br />
drop tcp any any  any any (msg:&#8221;DROP ALL&#8221;; content:&#8221;google.com&#8221;;       sid:3000010;)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

