# Does AF\_Packet now support the IPS mode?

**URL:** <https://forum.suricata.io/t/does-af-packet-now-support-the-ips-mode/964>\
**Category:** Help\
**Tags:** ips\
**Created:** [January 10, 2021, 4:26pm UTC](https://forum.suricata.io/t/does-af-packet-now-support-the-ips-mode/964 "2021-01-10T16:26:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![SecurityDad](https://avatars.discourse-cdn.com/v4/letter/s/9e8a1a/32.png) [@SecurityDad](https://forum.suricata.io/u/SecurityDad)\
**Post date:** [January 10, 2021, 4:26pm UTC](https://forum.suricata.io/t/does-af-packet-now-support-the-ips-mode/964/1 "2021-01-10T16:26:32Z")

</div>

I see on the features page ([All features | Suricata](https://suricata-ids.org/features/all-features/)), the following information:

### Packet acquisition

- High performance capture
  - AF\_PACKET
    - experimental eBPF and XDP modes available

  - PF\_RING
  - NETMAP

- Standard capture
  - PCAP
  - NFLOG (netfilter integration)

- IPS mode
  - Netfilter based on Linux (nfqueue)
    - fail open support

  - ipfw based on FreeBSD and NetBSD
  - AF\_PACKET based on Linux
  - NETMAP

- Capture cards and specialized devices
  - Endace
  - Napatech
  - Tilera

Does this mean that IPS is supported with the AF\_Packet? What is the performance difference with AF\_Packet and NFQueue?

---

<div class="post-metadata">

**Author:** ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)\
**Post date:** [January 11, 2021, 5:21pm UTC](https://forum.suricata.io/t/does-af-packet-now-support-the-ips-mode/964/2 "2021-01-11T17:21:08Z")

</div>

I can’t comment on the performance differences, but they do work somewhat difference. AF\_PACKET IPS works by copying the packets received on one interface to another, so its bridging the ethernet interfaces. So this may determine if AF\_PACKET can be used for you or not.

---

<div class="post-metadata">

**Author:** ![SecurityDad](https://avatars.discourse-cdn.com/v4/letter/s/9e8a1a/32.png) [@SecurityDad](https://forum.suricata.io/u/SecurityDad)\
**Post date:** [January 11, 2021, 5:40pm UTC](https://forum.suricata.io/t/does-af-packet-now-support-the-ips-mode/964/3 "2021-01-11T17:40:27Z")

</div>

Thank you @ish, this is perfect for an inline filter.

Does it still act like an IPS @ish or is the bridge still copying the content if it is told to drop it?

---

<div class="post-metadata">

**Author:** ![ish](https://yyz2.discourse-cdn.com/flex030/user_avatar/forum.suricata.io/ish/32/8_2.png) [@ish](https://forum.suricata.io/u/ish)\
**Post date:** [January 11, 2021, 7:28pm UTC](https://forum.suricata.io/t/does-af-packet-now-support-the-ips-mode/964/4 "2021-01-11T19:28:41Z")

</div>

> [@SecurityDad](#):
>
> Does it still act like an IPS @ish or is the bridge still copying the content if it is told to drop it?

It can still act as an IPS. Just pay attention to the `copy-mode` in your `af-packet` section when setting up the interfaces for the bridge.
