That was easy :-) I will try that and see how it goes. Thanks, Siva -----Original Message----- From: Martijn Lievaart [mailto:m@xxxxxxx] Sent: Sunday, April 22, 2007 10:45 PM To: Krishnamoorthy (Siva) Sivakumar Cc: Pascal Hambourg; netfilter@xxxxxxxxxxxxxxxxxxx Subject: Re: Iptables rule on span traffic Krishnamoorthy (Siva) Sivakumar wrote: > You could try to turn on forwarding and block all traffic that makes it > through the snort rules. > > HTH, > M4 > > [Siva:] > Can you explain in more detail (sorry I am a novice)? How do you turn on forwarding? Does this require the iptables machine to be inline (in addition to a regular firewall/router that does the actual forwarding)? > > http://www.google.nl/search?q=linux+forwarding :-) HTH, M4