Snort mailing list archives

Alert Leak?


From: joseph.warner () siemens com
Date: Tue, 28 Jan 2003 14:20:24 -0700


Hi,

I have a PC with two NIC cards, one configured for my internal network
and the other for my T1 connection.  I'm using ZoneAlarm to protect
the NIC/connection using the T1.  I have snort running on our internal
network and sometimes it generates alerts for activity that's being
blocked by ZoneAlarm on the external (T1) NIC.  How is this possible
since traffic isn't routable between the two NIC cards?  How is snort
able to see this traffic at all?

Thanks









-------------------------------------------------------------------------------
This message and any included attachments are from Siemens Medical Solutions 
Health Services Corporation and are intended only for the addressee(s).  
The information contained herein may include trade secrets or privileged or 
otherwise confidential information.  Unauthorized review, forwarding, printing, 
copying, distributing, or using such information is strictly prohibited and may 
be unlawful.  If you received this message in error, or have reason to believe 
you are not authorized to receive it, please promptly delete this message and 
notify the sender by e-mail with a copy to CSOffice () smed com.  Thank you


-------------------------------------------------------
This SF.NET email is sponsored by:
SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See!
http://www.vasoftware.com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: