Snort mailing list archives
Re: .i eth1
From: Matt Kettler <mkettler () evi-inc com>
Date: Fri, 21 Nov 2003 11:39:12 -0500
At 04:29 AM 11/21/2003, Timm Schneider wrote:
snort -c /etc/snort/snort.conf -A full -D and snort -c /etc/snort/snort.conf -i eth1-A full -D In my snort.conf the eth0 and eth1 are configurated, so the eth0 and eth1 Interface must be monitored.
Um, how did you "configurate" eth0 and eth1 in your snort.conf.. AFAIK you only specify addresses for HOME_NET, etc.. this doesn't have anything to do with what interfaces snort will listen on.
But when i say i- eth1 is than the eth0 also monitored like the conf File said?
No, because that's not what the conf file stated. It will listen on eth1, but will be looking for attacks going to the address ranges you specfied.
------------------------------------------------------- This SF.net email is sponsored by: SF.net Giveback Program. Does SourceForge.net help you be more productive? Does it help you create better code? SHARE THE LOVE, and help us help YOU! Click Here: http://sourceforge.net/donate/ _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- .i eth1 Timm Schneider (Nov 21)
- Re: .i eth1 Matt Kettler (Nov 21)