Snort mailing list archives
RE: Cant see alert for rule
From: "Tom Fulton" <tfulton9909 () comcast net>
Date: Wed, 2 Jun 2004 14:41:57 -0700
Interesting... My laptop (snortbox) is using a 100MB NIC My two other boxes are using the Intel 10/100/1000 NIC Since the little Linksys 10/100 5-port workgroup hub is in the middle, shouldn't it all level out to 100MB? If not, what can I do? This is a lab so no prob switching things around... Should I pull the laptop out of the equation and just run the two Intel 10/100/1000 NICs? (install Snort on the attacker? But if I do that, will I just end up with the same problem? thanks -----Original Message----- From: snort-users-admin () lists sourceforge net [mailto:snort-users-admin () lists sourceforge net] On Behalf Of Jeff Coppock Sent: Wednesday, June 02, 2004 2:20 PM To: snort-users () lists sourceforge net Subject: Re: [Snort-users] Cant see alert for rule On Wed, 2 Jun 2004 13:37:04 -0700 "Tom Fulton" <tfulton9909 () comcast net> wrote:
I pulled out my Linksys switch and put in an old 10/100 5-port workgroup hub. Same problem. Any one have any ideas?
10/100 hubs actually have a switch between the 10Mbps segment and the 100Mbps segment to provide connectivity between them. So, if the snort box is on a different speed link than the other PC's, the snort box will still not see any of the traffic between the other two PC's. jc -- Jeff Coppock Systems Engineer Diggin' Debian Admin and User ------------------------------------------------------- This SF.Net email is sponsored by the new InstallShield X.
From Windows to Linux, servers to mobile, InstallShield X is the one
installation-authoring solution that does it all. Learn more and evaluate today! http://www.installshield.com/Dev2Dev/0504 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users ------------------------------------------------------- This SF.Net email is sponsored by the new InstallShield X.
From Windows to Linux, servers to mobile, InstallShield X is the one
installation-authoring solution that does it all. Learn more and evaluate today! http://www.installshield.com/Dev2Dev/0504 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Cant see alert for rule Tom Fulton (Jun 02)
- RE: Cant see alert for rule Tom Fulton (Jun 02)
- Re: Cant see alert for rule Jeff Coppock (Jun 02)
- RE: Cant see alert for rule Tom Fulton (Jun 02)
- RE: Cant see alert for rule Tom Fulton (Jun 02)
- Re: Cant see alert for rule Jeff Coppock (Jun 02)
- RE: Cant see alert for rule Tom Fulton (Jun 02)
- <Possible follow-ups>
- RE: Cant see alert for rule Harper, Patrick (Jun 02)
- Re: Cant see alert for rule SN ORT (Jun 03)
- HOME_NET question sart (Jun 03)
- RE: Cant see alert for rule Tom Fulton (Jun 03)