Snort mailing list archives
Re: ADSL with Border IDS config problem
From: Erek Adams <erek () theadamsfamily net>
Date: Thu, 28 Feb 2002 03:34:00 -0800 (PST)
On Thu, 28 Feb 2002, Mysq wrote: [...snip...]
The problem: Snort doesn't log or alert to any attacks or portscans coming in from the internet. (nmap using different options and the site Shields up which port scans your IP and displays results). I checked to see if the actual installation works by connecting a machine to Hub1 and running a portscan - snort picked it up successfully. When a portscan is run from the internet on the firewall public IP (ppp0) - snort doesn't pick it up.
[...snip...] To just take a guess, I'd bet it was a auto-sensing hub. With that in mind, I'd also think that http://www.snort.org/docs/faq.html#6.21 is the key to your problem. Cheers! ----- Erek Adams Nifty-Type-Guy TheAdamsFamily.Net _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- ADSL with Border IDS config problem Mysq (Feb 28)
- Re: ADSL with Border IDS config problem Erek Adams (Feb 28)