Snort mailing list archives

Re: .i eth1


From: Matt Kettler <mkettler () evi-inc com>
Date: Fri, 21 Nov 2003 11:39:12 -0500

At 04:29 AM 11/21/2003, Timm Schneider wrote:
snort -c /etc/snort/snort.conf -A full -D
and
snort -c /etc/snort/snort.conf  -i eth1-A full -D

In my snort.conf the eth0 and eth1 are configurated,
so the eth0 and eth1 Interface must be monitored.

Um, how did you "configurate" eth0 and eth1 in your snort.conf.. AFAIK you only specify addresses for HOME_NET, etc.. this doesn't have anything to do with what interfaces snort will listen on.

But when i say i- eth1 is than the eth0 also monitored like
the conf File said?

No, because that's not what the conf file stated. It will listen on eth1, but will be looking for attacks going to the address ranges you specfied.


-------------------------------------------------------
This SF.net email is sponsored by: SF.net Giveback Program.
Does SourceForge.net help you be more productive?  Does it
help you create better code?  SHARE THE LOVE, and help us help
YOU!  Click Here: http://sourceforge.net/donate/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: