Snort mailing list archives

RE: interface on promiscuous mode ?


From: "Slighter, Tim" <tslighter () itc nrcs usda gov>
Date: Fri, 22 Mar 2002 12:52:36 -0700

It goes into promiscuous mode automatically unless specified to NOT do so
with the -p switch.  However, when you run snort you will need to run with
the -i eth0.  Does that help?

-----Original Message-----
From: Ashley Thomas [mailto:athomas () unity ncsu edu]
Sent: Friday, March 22, 2002 11:11 AM
To: snort-users () lists sourceforge net
Subject: [Snort-users] interface on promiscuous mode ?


hi,

i am setting up snort on a linux machine and needs the ethernet interface
to be in stealth mode.

so i did a simple "ifconfig eth0 up"

and see the ifconfig -a as:

eth1      Link encap:Ethernet  HWaddr 00:03:86:45:BB:77
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:1029434 errors:0 dropped:0 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100
          Interrupt:5 Memory:f9000000-f9020000


But i see only arp and broadcast packets when i do a tcpdump -i eth1

Looking at /var/log/messages, i don't see "device eth1 entered promiscuous
mode"

Is this the problem ? How do i make it go into promiscuous mode ?

thanks



_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: