Snort mailing list archives
Re: Very basic question
From: Matt Kettler <mkettler () evi-inc com>
Date: Wed, 21 May 2003 14:52:14 -0400
This is FAQ 3.2 of the version of the FAQ on the website: http://www.snort.org/docs/faq.html#3.2 you just don't configure the interface and then force it up with ifup. From there snort can sniff packets just fine..and before you ask, yes you can have IPTables blocking packets and snort will still see them.. snort sniffs at the ethernet level, not the IP stack level.
At 01:55 PM 5/21/2003 -0400, Ryan Koster wrote:
Sorry for a basic question but I am new to all this. I am running Redhat 9 with two nics. I would like to set eth0 with no ip address but still be able to listen for IP traffic. Can someone please tell me how this is done?
------------------------------------------------------- This SF.net email is sponsored by: ObjectStore. If flattening out C++ or Java code to make your application fit in a relational database is painful, don't do it! Check out ObjectStore. Now part of Progress Software. http://www.objectstore.net/sourceforge _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Very basic question Ryan Koster (May 21)
- Re: Very basic question Demetri Mouratis (May 21)
- <Possible follow-ups>
- Re: Very basic question Matt Kettler (May 21)
- RE: Very basic question Tinsley Paul (May 21)