Snort mailing list archives

series of questions


From: "succendo" <succendo () AtlasWebmail com>
Date: Sun, Aug 5 2001 22:16:54

this is prolly a really stupid user error or maybe there all
related but here it goes.  first of all, I'm running snort on
a linux ipmasq (or nat) server with 2 nics one (eth0) is the
connection out, and one (eth1) is my internal lan. if I set it
up to monitor eth1 and then do something to anger it, like a
portscan from an internal box it reacts, but when its configured
to watch eth0 and I attempt to anger it using a shell it doesn't
react at all. when it is killed it says that it saw the packets
but no alerts. also I'm running it on a 486 sx with 10 megs of
ram the bandwidth is comperable to a t1 down stream but up stream
is only 15 kbps. is that enough horse power? thanks alot.

--Succendo


____________________________________
A t l a s W e b m a i l . c o m 


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: