Snort mailing list archives

Re: Snort Inline Bridge


From: webcatalog () mac com
Date: Mon, 3 Mar 2003 12:14:30 -0600

Thanks Tim, I've been all over it. Still don't see it, guess I will have to play with it for a while before I see it. I must be the only one doing it cause no one has an easy answer. :(

On Monday, March 3, 2003, at 11:58 AM, Slighter, Tim wrote:

Check out the project for using snort-inline with bridge on honeynet @
http://www.honeynet.org/papers/honeynet/tools/

-----Original Message-----
From: webcatalog () mac com [mailto:webcatalog () mac com]
Sent: Monday, March 03, 2003 10:31 AM
To: SnortUsers
Subject: [Snort-users] Snort Inline Bridge


I wanna use Snort Inline with a Bridge. I will be supporting multiple
networks behind the bridge. How do I setup the rc.firewall script to do
this.


Here is a snippet from the script:

### Variable for external network
INET_IFACE="eth0"                       # Firewall Public interface

### Variables for internal network
LAN_IFACE="eth1"                        # Firewall interface on
internal network
LAN_IP_RANGE="192.168.0.0/24"           # IP Range of internal network
LAN_BCAST_ADRESS="192.168.0.255"        # IP Broadcast range for
internal network

my lan ip ranges will be 2 complete separate networks.

ie 172.16.1.0 and 10.0.0.1

Do I need to set the LAN_IP_RANGE can it be space delimited?
If so what about the LAN_BCAST_ADRESS


Robert Minor
____________________________________
http://www.cybermill.com
Development, Hosting, Colocation on a multihomed DS3.

When my brother told me he had found Jesus,
I thought "Yahoo were rich" but it turned out to be something different.



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: