On Tue, Feb 23, 2010 at 12:40 AM, Johan Beisser <j...@caustic.org> wrote: > On Mon, Feb 22, 2010 at 8:53 PM, Jason Beaudoin <jasonbeaud...@gmail.com> wrote: > >> - in terms of BroIDS/Snort and PF.. who comes first in processing >> network traffic? > > hardware interface > kernel device driver > bpf/pcap -->> application (tcpdump, snort, BroIDS, etc) > packet filter (PF) >
thanks you Johan!