Snort mailing list archives

Re: Active response on two interfaces


From: Russ Combs <rcombs () sourcefire com>
Date: Wed, 9 May 2012 00:57:30 -0400

What version of Snort and DAQ are you using?  Snort has a check to prevent
RST to RST.

On Tue, May 1, 2012 at 7:46 PM, Jon Larson <jlarson () catbird com> wrote:

I/we need to get snort to operate on two interfaces.  For simplicity,
let's just say I want to have snort monitor traffic on eth0, but then
send its resets out on eth1.  What's the configuration magic to allow this?

I've tried something like this in the snort.conf:
config response: device eth1 attempts 2

This, however, seems to get snort into this mode (when it detects some
TCP connection it's configured to reset) where it "sniffs" back in the
RST packet (on the other interface), then sends another RST packet.
Kinda like "eating it's own tail".  The snort process consumes the CPU
and floods the network in this mode.

Also is there documentation someone could point me to regarding
configuring snort for multiple interfaces?

Any and all information would be greatly appreciated!
Jonny L.



------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and
threat landscape has changed and how IT managers can respond. Discussions
will include endpoint security, mobile security and the latest in malware
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-devel mailing list
Snort-devel () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-devel mailing list
Snort-devel () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!

Current thread: