next up previous contents
Next: Control socket Up: Snort Modes Previous: Snort Modes   Contents

Explanation of Modes

Behavior of different modes with rule options

Rule Option Inline Mode Passive Mode Inline-Test Mode
reject Drop + Response Alert + Response Wdrop + Response
react Blocks and send notice Blocks and send notice Blocks and send notice
normalize Normalizes packet Doesn't normalize Doesn't normalize
replace replace content Doesn't replace Doesn't replace
respond close session close session close session

Behavior of different modes with rules actions

Adapter Mode Snort args config policy_mode Drop Rule Handling
Passive -treat-drop-as-alert tap Alert
Passive no args tap Not Loaded
Passive -treat-drop-as-alert inline_test Alert
Passive no args inline_test Would Drop
Passive -treat-drop-as-alert inline Alert
Passive no args inline Not loaded + warning
Inline Test -enable-inline-test -treat-drop-as-alert tap Alert
Inline Test -enable-inline-test tap Would Drop
Inline Test -enable-inline-test -treat-drop-as-alert inline_test Alert
Inline Test -enable-inline-test inline_test Would Drop
Inline Test -enable-inline-test -treat-drop-as-alert inline Alert
Inline Test -enable-inline-test inline Would Drop
Inline -Q -treat-drop-as-alert tap Alert
Inline -Q tap Alert
Inline -Q -treat-drop-as-alert inline_test Alert
Inline -Q inline_test Would Drop
Inline -Q -treat-drop-as-alert inline Alert
Inline -Q inline Drop


next up previous contents
Next: Control socket Up: Snort Modes Previous: Snort Modes   Contents
Eugene Misnik 2013-05-08