@evadon, wait..."intrusion prevention"...Snort has block capability in OpenWrt?
If so, can you tell us how?
What's on line 326 of the snort.conf
file? Just a bracket?
I've ran Snort on a VM (pfSense) , perhaps I need to do more testing. I usually spin up router VMs with 256 MB. If the OP were to load a lot of rules, I'd definitely agree.