Snort mailing list archives

Re: ADSL with Border IDS config problem


From: Erek Adams <erek () theadamsfamily net>
Date: Thu, 28 Feb 2002 03:34:00 -0800 (PST)

On Thu, 28 Feb 2002, Mysq  wrote:


[...snip...]

The problem:
Snort doesn't log or alert to any attacks or
portscans coming in from the
internet. (nmap using different options and the
site Shields up which port
scans your IP and displays results).
I checked to see if the actual installation
works by connecting a machine to
Hub1 and running a portscan - snort picked it up
successfully. When a portscan is run from the
internet on the firewall
public IP (ppp0) - snort doesn't pick it up.

[...snip...]

To just take a guess, I'd bet it was a auto-sensing hub.  With that in mind,
I'd also think that http://www.snort.org/docs/faq.html#6.21 is the key to your
problem.

Cheers!

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: