Snort mailing list archives

RE: Ipchains questions


From: Ciaron Gogarty <cgogarty () lancomms ie>
Date: Mon, 27 Aug 2001 16:56:42 +0100

depends on what type of switch.  If it's a cisco ios based then under the
interface snort is connected to type "port mirror?"  this will give you the
syntax you need.

If it's a cisco cat os switch its 
span port ? or perhaps port span, can never remember.

Cheers,

C

-----Original Message-----
From: Darrin Powell [mailto:dpowell () lssi net]
Sent: 27 August 2001 15:52
To: Blake Frantz
Cc: snort-users () lists sourceforge net
Subject: Re: [Snort-users] Ipchains questions



   Yes I am connected through a switch. I am not familiar with how to port 
mirror. Could you give me some more info on that or possibly a website.



Thanks for the reply
Darrin





On Friday 24 August 2001 05:32 pm, Blake Frantz wrote:
Is your snort sensor hung off a switch or hub ?  if it's off a switch
then you won't see anything destined to other boxes unless you port
mirror.

-blake

=================================================================
The Government, like diapers, should be replaced regularly, and
often for the same reasons.

On Fri, 24 Aug 2001, Darrin Powell wrote:
   Ok here is my scenario I have a box outside the firewall with a deny
all ipchians approach running snort. If I scan that box snort picks it
up. In my snort rules I have multiple ip address that I want snort to
monitor.

 var HOME_NET [111.111.111.112,111.111.111.113,111.111.111.114]


The rest of the configuration is pretty much default for snort-1.8p1-0.
Other than location of rules and conf file.

These other machines have ipchains as well with a deny all approach. If
I
scan any of those boxes snort does not pick it up. Should snort pick up
these other machines or do I have to change my ichains so they can see
eachother?






 Thanks in advance
Darrin


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: