Snort mailing list archives

Re: Snort with two sniffing interfaces


From: Alejandro Cabrera Obed <aco1967 () gmail com>
Date: Fri, 14 May 2010 11:13:09 -0300

I tell you I've used two instances of Snort:

One for the sniffing interface #1 and the second for the sniffing interface #2.

So the result is I get both traffic and Snort analyze them succesfully.

Thanks a lot !!!

Alejandro

2010/5/11 Joel Esler <jesler () sourcefire com>:
Yes, Seth.  It's possible.

On Tue, May 11, 2010 at 4:48 PM, Seth Art <sethsec () gmail com> wrote:

Also not really familiar with snort on windows, but you should be able
to run two instances, each with their own sniffing interface, right?

-Seth

On Tue, May 11, 2010 at 11:54 AM, Jason Wallace
<jason.r.wallace () gmail com> wrote:
Under Linux this is possible if you bond the NIC's and then do:

snort -i bond0

I do not know if the same can be done under Windows...


Wally

On Tue, May 11, 2010 at 11:37 AM, Max Williams <Max.Williams () mflow com>
wrote:
Someone may correct me but I'm pretty sure this is not possible. I
wanted to achieve the same, googled and tried various command switches like
you but no luck. I don't think its possible even in Linux (?). I think you
have to run two snort processes with separate config files or different
command switches.

Cheers,
Max

-----Original Message-----
From: Alejandro Cabrera Obed [mailto:aco1967 () gmail com]
Sent: 11 May 2010 16:32
To: snort-users () lists sourceforge net
Subject: [Snort-users] Snort with two sniffing interfaces

Dear all, I have a Snort IDS under Windows with two sniffing
interfaces (#2 and #3).

How can I tell Snort from command line to listen to both sniffing
interfaces, the next is correct ???

snort -i2 -i3 .......or snort -i23 .............

Thanks for your help.

Alejandro


------------------------------------------------------------------------------

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


------------------------------------------------------------------------------

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



------------------------------------------------------------------------------

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users



------------------------------------------------------------------------------

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


------------------------------------------------------------------------------


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users




-- 
Alejandro Cabrera Obed
aco1967 () gmail com
www.alejandrocabrera.com.ar

------------------------------------------------------------------------------

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: