Snort mailing list archives
series of questions
From: "succendo" <succendo () AtlasWebmail com>
Date: Sun, Aug 5 2001 22:16:54
this is prolly a really stupid user error or maybe there all related but here it goes. first of all, I'm running snort on a linux ipmasq (or nat) server with 2 nics one (eth0) is the connection out, and one (eth1) is my internal lan. if I set it up to monitor eth1 and then do something to anger it, like a portscan from an internal box it reacts, but when its configured to watch eth0 and I attempt to anger it using a shell it doesn't react at all. when it is killed it says that it saw the packets but no alerts. also I'm running it on a 486 sx with 10 megs of ram the bandwidth is comperable to a t1 down stream but up stream is only 15 kbps. is that enough horse power? thanks alot. --Succendo ____________________________________ A t l a s W e b m a i l . c o m _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- series of questions succendo (Aug 04)
- Re: series of questions John Sage (Aug 05)
- <Possible follow-ups>
- Re: series of questions jrd (Aug 05)
- Re: series of questions Alex David Shadrach Hooper (Aug 06)
- Re: series of questions Alex David Shadrach Hooper (Aug 06)
- Re: series of questions Alex David Shadrach Hooper (Aug 06)