Snort mailing list archives

monitoring only occuring on snort host


From: "Ted Iglehart" <ted () techteaminc com>
Date: Mon, 2 Feb 2004 17:22:20 -0600

I am running Snort on a W2k server with the box placed between my
firewall and the Internet.
 
I appear to have everything configured correctly with my home network
set to x.x.x.x/24
 
However, I only appear to be catching events that are actually hitting
the snort box and not the subnet as a whole?
 
Is there a FAQ or screen shots of an IDS setup that a newbie can review
other than what is available on snort.org?
 
I am wondering if my Available IP's which only list the snort box should
have my x.x.x.x/24 listed?  I have tried this without success.  I feel
that I am sooo close.
 
 
 
 

Current thread: