diff --git a/docs/FAQ.xml b/docs/FAQ.xml index 161a9f937..2528f222c 100644 --- a/docs/FAQ.xml +++ b/docs/FAQ.xml @@ -2619,5 +2619,16 @@ loc $FW ACCEPT loc->$FW since those rules are redundant with the above policies. + +
+ (FAQ 87) Can I run Snort with Shorewall? + + Answer: Yes. In Network + Intrusion Detection System (NIDS) mode, Snort is libpcap + based (like tcpdump) so it doesn't interfere with Shorewall. We have had + reports that users have also been successful in using Snort in + inline more with Shorewall, but no HOWTO exists at + this time. +