Snort mailing list archives
Re: Snort with IPTables
From: Fyodor <fygrave () tigerteam net>
Date: Sun, 13 Jan 2002 22:50:37 +0700
On Sun, Jan 13, 2002 at 09:06:03AM -0600, David Lambert wrote:
I have very Little knowledge in this arena, so please excuse my ignorance, but doesn't the -p (promiscuous) flag have something to do with whether or not snort sees network traffic before an internal firewall? If this is just bunk, then could someone please point me to an explanation (better than that in the snort man page) of what the -p flag does?
Shortly, promiscious mode: if on --> listens to all the traffic in the network, if off --> listens to only traffic which is destined to your network interface. _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort with IPTables jaalexan (Jan 10)
- Re: Snort with IPTables Mark Rowlands (Jan 12)
- Re: Snort with IPTables Erek Adams (Jan 12)
- Message not available
- Re: Snort with IPTables Matt Kettler (Jan 12)
- Re: Snort with IPTables Erek Adams (Jan 12)
- RE: Snort with IPTables Martijn Heemels (Jan 13)
- Re: Snort with IPTables Hasnain Atique (Jan 13)
- RE: Snort with IPTables neal (Jan 14)
- Re: Snort with IPTables David Lambert (Jan 13)
- Re: Snort with IPTables Fyodor (Jan 13)
- Re: Snort with IPTables John Sage (Jan 13)
- Re: Snort with IPTables Mark Rowlands (Jan 12)