Does ASL support the use of the ip_queue module and the QUEUE target in its distrubution of IPTABLES?
I have Snort up and running on my ASL box and all is fine. However, I'd like to switch to Snort inline in Queue mode to use it for selective Intrusion Prevention for certain packet filter rules. I would Queue all inbound traffic on certain ports but leave the rest un-scanned. I'd use Snort, in "IDS mode", on a separate machine.
I want to block known attacks on certain ports.
What do you think are the odds that Astaro will add a QUEUE option to the list of available actions in the packet filter rules?
Now all I'd have to do is get ASL to allow me to access SnortSnarf through it's webserver!