Snort mailing list archives
BPF filters and Demarc
From: Gary Danko <GDanko () proflowers com>
Date: Mon, 28 Jul 2003 16:01:05 -0700
I tried launching snort from the command line with and without the switch for the BPF filter file. Here are my results. Without: [root@ids1 conf]$ /usr/local/bin/snort -o -de -i eth1 -c /usr/local/demarc/conf/snorteth1-a.conf Running in IDS mode Log directory = /var/log/snort Initializing Network Interface eth1 OpenPcap() device eth1 network lookup: eth1: no IPv4 address assigned --== Initializing Snort ==-- Rule application order changed to Pass->Alert->Log Initializing Output Plugins! Decoding Ethernet on interface eth1 Initializing Preprocessors! Initializing Plug-ins! Parsing Rules file /usr/local/demarc/conf/snorteth1-a.conf +++++++++++++++++++++++++++++++++++++++++++++++++++ Initializing rule chains... No arguments to frag2 directive, setting defaults to: Fragment timeout: 60 seconds Fragment memory cap: 4194304 bytes Fragment min_ttl: 0 Fragment ttl_limit: 5 Fragment Problems: 0 Self preservation threshold: 500 Self preservation period: 90 Suspend threshold: 1000 Suspend period: 30 Stream4 config: Stateful inspection: ACTIVE Session statistics: INACTIVE Session timeout: 30 seconds Session memory cap: 8388608 bytes State alerts: INACTIVE Evasion alerts: INACTIVE Scan alerts: ACTIVE Log Flushed Streams: INACTIVE MinTTL: 1 TTL Limit: 5 Async Link: 0 State Protection: 0 Self preservation threshold: 50 Self preservation period: 90 Suspend threshold: 200 Suspend period: 30 Stream4_reassemble config: Server reassembly: INACTIVE Client reassembly: ACTIVE Reassembler alerts: ACTIVE Ports: 21 23 25 53 80 110 111 143 513 1433 Emergency Ports: 21 23 25 53 80 110 111 143 513 1433 http_decode arguments: Unicode decoding IIS alternate Unicode decoding IIS double encoding vuln Flip backslash to slash Include additional whitespace separators Ports to decode http on: 80 rpc_decode arguments: Ports to decode RPC on: 111 32771 alert_fragments: INACTIVE alert_large_fragments: ACTIVE alert_incomplete: ACTIVE alert_multiple_requests: ACTIVE telnet_decode arguments: Ports to decode telnet on: 21 23 25 119 database: compiled support for ( mysql ) database: configured to use mysql database: user = snort database: database name = snort database: password is set database: host = 10.1.30.60 database: sensor name = ids1 database: sensor id = 2 database: schema version = 106 database: using the "log" facility 0 Snort rules read... 0 Option Chains linked into 0 Chain Headers 0 Dynamic rules +++++++++++++++++++++++++++++++++++++++++++++++++++ Rule application order: ->pass->activation->dynamic->alert->log --== Initialization Complete ==-- -*> Snort! <*- Version 2.0.0 (Build 72) By Martin Roesch (roesch () sourcefire com, www.snort.org) And with: [root@ids1 conf]$ /usr/local/bin/snort -F /usr/local/demarc/conf/bpf-filters.conf -o -de -i eth1 -c /usr/local/demarc/conf/snorteth1-a.conf Running in IDS mode Log directory = /var/log/snort Initializing Network Interface eth1 OpenPcap() device eth1 network lookup: eth1: no IPv4 address assigned ERROR: OpenPcap() FSM compilation failed: PCAP command: %s Fatal Error, Quitting.. Here is the contents of my bpf filter: [root@ids1 conf]$ more bpf-filters.conf !host 192.168.1.10 !host 10.2.20.20 !host 10.2.20.30 ------------------------------------------------------- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals, and Forums are available now. Download today and enter to win an XBOX or Visual Studio .NET. http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- BPF filters and Demarc Gary Danko (Jul 28)
- <Possible follow-ups>
- BPF filters and Demarc Gary Danko (Jul 28)
- Re: BPF filters and Demarc Erek Adams (Jul 29)
- RE: BPF filters and Demarc Gary Danko (Jul 28)