Snort mailing list archives
Re: (no subject)
From: Erek Adams <erek () snort org>
Date: Tue, 5 Aug 2003 10:11:43 -0400 (EDT)
On Tue, 5 Aug 2003, RAJNEEL DHOTRE wrote:
Few questions. I have installed Snort and updated rules via internet. 1) Can snort detect and drop packet. How do i configure this ?
Yes. ./configure --with-flexresp
2) Can Snort act as NIDS ? How do i configure this ?
Yes. snort -c /etc/snort.conf After you've configured snort.conf for your network of course.
3) Do i have to configure port mirroring on my switch.
Yes. Cheers! ----- Erek Adams "When things get weird, the weird turn pro." H.S. Thompson ------------------------------------------------------- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals, and Forums are available now. Download today and enter to win an XBOX or Visual Studio .NET. http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01 _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Re: ICMP Source Quench, (continued)
- Re: ICMP Source Quench Chris Green (Jul 07)
- RE: ICMP Source Quench Bryan Waters (Jul 07)
- RE: ICMP Source Quench twig les (Jul 07)
- Re: (no subject) Chris Green (Aug 06)
- Re: (no subject) Erek Adams (Aug 05)
- Re: (no subject) Matt Kettler (Aug 05)
- Re: (no subject) Patrick S. Harper - CISSP (Aug 05)
- Re: (no subject) Stefan Eggert (Aug 26)
- Re: (no subject) Nick Oliver (Sep 08)
- RE: (no subject) Edward Marshall (Sep 19)