pfsense:suricata:inline_versus_legacy_ips_mode
Differences
This shows you the differences between two versions of the page.
pfsense:suricata:inline_versus_legacy_ips_mode [2021/01/20 12:56] – created peter | pfsense:suricata:inline_versus_legacy_ips_mode [2021/01/20 12:57] (current) – peter | ||
---|---|---|---|
Line 17: | Line 17: | ||
* Packets that subsequently come through from the same IP address will now get blocked, though. | * Packets that subsequently come through from the same IP address will now get blocked, though. | ||
+ | ---- | ||
- | | + | |
- | A true IPS would hold up the original packet while it was being inspected, and then either pass it or drop it. | + | |
- | Legacy mode does not hold up the original packet. | + | |
- | It is allowed to continue on to the firewall while the cloned copy is used to make the decision for blocking future packets from the IP address. | + | |
pfsense/suricata/inline_versus_legacy_ips_mode.1611147407.txt.gz · Last modified: 2021/01/20 12:56 by peter