Snort mailing list archives

snort kvm network


From: Emilio Joel Macias <emilio () deenero com>
Date: Sun, 21 Dec 2014 15:13:41 +0100

I have installed two physical machines with KVM virtualization using Red
hat as OS ( h1 and h2). In h1 I have installed the virtual machines w1 and
db1 and in h2 the virtual machines w2 , db1 and ids. The virtual machine
ids contain snort as IDS system. After the installation i ran the command:

brctl setageing br0 0

in order to permit snort sniff the network traffic but only is passing the
traffic related with the physical machine h2 which is the Host the snort
machine but nothing related with machine h1 and their virtual Guests.

Is possible with snort installed in a KVM virtual machine detect the
traffic of the rest of machines in the network or only can detect the
traffic of the machines sharing the same bridge?

thanks
------------------------------------------------------------------------------
Download BIRT iHub F-Type - The Free Enterprise-Grade BIRT Server
from Actuate! Instantly Supercharge Your Business Reports and Dashboards
with Interactivity, Sharing, Native Excel Exports, App Integration & more
Get technology previously reserved for billion-dollar corporations, FREE
http://pubads.g.doubleclick.net/gampad/clk?id=164703151&iu=/4140/ostg.clktrk
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: