Snort mailing list archives

Re: RE: Snort-1.8.7 detection problems


From: Chris Green <cmg () sourcefire com>
Date: Mon, 22 Jul 2002 10:37:52 -0400

chae <chae () hyper net nz> writes:

Hi Yah,

Wojtek stated...

"..Compilation, etc, seem to be ok. There's no different version of
pcap. Effect is that i get only icmp (not firewall problem) captured
packets. I can say that my previous version of snort had no problems
with tcp/icmp, but was similar problem with udp. This is not a problem
of sql too, because normal logging give the same. This is strange for
me that every version of snort has problems in my case with capturing
specific protocol. Any ideas will be appreciated."

This is the same problem I've been plagued with, even after numerous
reinstalls, force installs and using the latest rule sets etc.

I'd appreciate any suggestions also.

OS Version?
Do you see the same behavior from tcpdump?
-- 
Chris Green <cmg () sourcefire com>
Eschew obfuscation.


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: