Hi there,
I was just wondering if it was possible to prevent snort from seeing packets that have been dropped by iptables. I believe this would be possible if openwrt supported NFQ and then you could use that to pass the packets to snort after they have been filtered. But is there a way to do this on openwrt?
Basically I don't want snort to see packets that have been dropped by iptables or ebtables.