Snort mailing list archives

network issue?


From: kinomakino <kinomakino () hotmail com>
Date: Tue, 9 Sep 2014 10:55:57 +0200

First, thanks for the help. 
I have an install of snort on a vps with a setting of "weird" for my
network. 
I put the ifconfig. 
All decisions of the webservers DNS point to the IP of eth2: 1 

If I put on snort eth2: 1 HOMENET and put that IP, I have only one traffic
alerts TOR rule (emerging). if I do the same "attacks" against another snort
with the same rules, if I see the alerts, so that alerts are not. 
I think it's the network. 

You can help me with this? 
Thank you! 

eth2 Link encap: Ethernet HWaddr 00: 25: 90: 82: BA: A6 
           inet addr: PUBLIC IP Bcast: **** Mask: 255.255.255.0 
           BROADCAST RUNNING MULTICAST MTU UP: 1500 Metric: 1 
           RX packets: 325077067 errors: 0 dropped: 0 overruns: 0 frame: 0 
           TX packets: 478271928 errors: 0 dropped: 0 overruns: 0 carrier: 0

           collisions: 0 txqueuelen: 1000 
           RX bytes: 204005183266 (189.9 GiB) TX bytes: 441 545 055 832
(411.2 GiB) 

eth2: 1 Link encap: Ethernet HWaddr 00: 25: 90: 82: BA: A6 
           inet addr: PUBLIC Bcast IP: ****** Mask: 255.255.255.255 
           BROADCAST RUNNING MULTICAST MTU UP: 1500 Metric: 1 

eth2: 2 Link encap: Ethernet HWaddr 00: 25: 90: 82: BA: A6 
           inet addr: PUBLIC IP Bcast: 188165133135 Mask: 255.255.255.255 
           BROADCAST RUNNING MULTICAST MTU UP: 1500 Metric: 1

------------------------------------------------------------------------------
Want excitement?
Manually upgrade your production database.
When you want reliability, choose Perforce.
Perforce version control. Predictably reliable.
http://pubads.g.doubleclick.net/gampad/clk?id=157508191&iu=/4140/ostg.clktrk
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: