On Tue, Feb 23, 2010 at 12:40 AM, Johan Beisser <[email protected]> wrote: > On Mon, Feb 22, 2010 at 8:53 PM, Jason Beaudoin <[email protected]> wrote: > >> - in terms of BroIDS/Snort and PF.. who comes first in processing >> network traffic? > > hardware interface > kernel device driver > bpf/pcap -->> application (tcpdump, snort, BroIDS, etc) > packet filter (PF) >
thanks you Johan!

