Snort mailing list archives

Re: Very basic question


From: Matt Kettler <mkettler () evi-inc com>
Date: Wed, 21 May 2003 14:52:14 -0400

This is FAQ 3.2 of the version of the FAQ on the website:
http://www.snort.org/docs/faq.html#3.2

you just don't configure the interface and then force it up with ifup.

From there snort can sniff packets just fine..

and before you ask, yes you can have IPTables blocking packets and snort will still see them.. snort sniffs at the ethernet level, not the IP stack level.


At 01:55 PM 5/21/2003 -0400, Ryan Koster wrote:
Sorry for a basic question but I am new to all this. I am running Redhat 9 with two nics. I would like to set eth0 with no ip address but still be able to listen for IP traffic. Can someone please tell me how this is done?



-------------------------------------------------------
This SF.net email is sponsored by: ObjectStore.
If flattening out C++ or Java code to make your application fit in a
relational database is painful, don't do it! Check out ObjectStore.
Now part of Progress Software. http://www.objectstore.net/sourceforge
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: