|
What you want with snort, is basicaly a machine that will handle a vast amount of network trafic without seeming to slow the network activity down..
*BSD's network-stack was previusly a great deal faster than the linux stack, but since kernel 2.6.x theres virtualy not much difference between the two.
But since once uppon a time in the west.. the prefered system used to be *BSD, the implementation is widely performed on *BSD boxes.
(I hope KK want's to dip in on this)
|