Snort mailing list archives
Snort with IPTables
From: <jaalexan () rockwellcollins com>
Date: Thu, 10 Jan 2002 10:50:49 -0600
Hello all, I have done some reading of the archived message but I still have a few questions about Snort with IP Tables. First some info about our environment. I have a small SOHO setup where I have a cable modem providing the internet connection. We have one linux server that has IP Tables on it with a IP Masq subnet behind it. The server also runs various services (Web, Mail, SSH) and has those ports open on the firewall. The external interface is eth1 and the internal interface is eth0. I would like to be able to put Snort on this box to determine how much abuse we are getting. From the archive it seems like this is possible but I am not sure. Idealy I would like to bind snort to eth1 so I can see all the traffic that is coming at the firewall and then some how bind it also to eth0 to determine what is making it past the rule set of the firewall. But If I am forced to I would be happy to have it sitting on external interface. Thanks Jason Alexander ------- My comments are mine and mine only. They do not reflect anyone else. _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort with IPTables jaalexan (Jan 10)
- Re: Snort with IPTables Mark Rowlands (Jan 12)
- Re: Snort with IPTables Erek Adams (Jan 12)
- Message not available
- Re: Snort with IPTables Matt Kettler (Jan 12)
- Re: Snort with IPTables Erek Adams (Jan 12)
- RE: Snort with IPTables Martijn Heemels (Jan 13)
- Re: Snort with IPTables Hasnain Atique (Jan 13)
- RE: Snort with IPTables neal (Jan 14)
- Re: Snort with IPTables David Lambert (Jan 13)
- Re: Snort with IPTables Fyodor (Jan 13)
- Re: Snort with IPTables John Sage (Jan 13)
- Re: Snort with IPTables Mark Rowlands (Jan 12)