I have a debian sarge 3.1 stable 2.6.I got fwsnort which promises to translate snort rules into iptables rules does anyone ever used this prog ?To translate snort rules it needs a module called MATCH if i'm not wrong that reads --hexadecimals and is avialable in the iptables version i have but when i launch fwsnort it still says:
argo:~# fwsnort[*] It does not appear that string match support has been compiled into
Netfilter. Fwsnort will not be of very much use without this.
** NOTE: If you want to have fwsnort generate a Netfilter policy
anyway, specify the --no-ipt-test option. Exiting.
i called the modprobe ipt_MARK and the ipt_mac and the ipt_mark all related to --hex in my firewall script but still doesn't work i'm sure missing something please help ... cheeeeeeeers!
