snort vs iptables

55 views
Skip to first unread message

Yassine el

unread,
Apr 12, 2016, 3:10:11 AM4/12/16
to snortreport-users
Hy,
i have a question about the performance of linux firewall such a Netfilter or NFTables tools in comparaison with the well knowen ids/ips firewall like Suricata and Snort, i know that Netfilter apply the match procedure in the kernel space, but the other open source firewall apply these rules in the userspace part, does it mean that thing goes more faster in Netfilter? Is there any kind of resource ( book, paper,..) That discuss such a subject?
Reply all
Reply to author
Forward
0 new messages