Snort mailing list archives
Re: stealth interface question
From: Brian <bmc () snort org>
Date: Wed, 12 Dec 2001 22:14:57 -0500
According to Merrick, Gary:
My Snort box has a stealth interface that doesn't have an IP address, and it seems to work very well. Is there any reason to also use a read-only cable?
Yes. If the inside network is on an internal network, it may be compromized from the inside and allow someone on the inside to bypass firewall/router filters. -- "Ummm, excuse me. I think the network's down...?" "A communications disruption can only mean one thing... Invasion." _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- stealth interface question Merrick, Gary (Dec 12)
- Re: stealth interface question Andy Steingruebl (Dec 12)
- Re: stealth interface question Brian (Dec 13)
- <Possible follow-ups>
- Re: stealth interface question Mike Shaw (Dec 12)
- Re: stealth interface question Fyodor (Dec 12)