Snort mailing list archives
Alert Leak?
From: joseph.warner () siemens com
Date: Tue, 28 Jan 2003 14:20:24 -0700
Hi, I have a PC with two NIC cards, one configured for my internal network and the other for my T1 connection. I'm using ZoneAlarm to protect the NIC/connection using the T1. I have snort running on our internal network and sometimes it generates alerts for activity that's being blocked by ZoneAlarm on the external (T1) NIC. How is this possible since traffic isn't routable between the two NIC cards? How is snort able to see this traffic at all? Thanks ------------------------------------------------------------------------------- This message and any included attachments are from Siemens Medical Solutions Health Services Corporation and are intended only for the addressee(s). The information contained herein may include trade secrets or privileged or otherwise confidential information. Unauthorized review, forwarding, printing, copying, distributing, or using such information is strictly prohibited and may be unlawful. If you received this message in error, or have reason to believe you are not authorized to receive it, please promptly delete this message and notify the sender by e-mail with a copy to CSOffice () smed com. Thank you ------------------------------------------------------- This SF.NET email is sponsored by: SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See! http://www.vasoftware.com _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Alert Leak? joseph . warner (Jan 29)