Snort mailing list archives

Question on snort redirecting


From: WAN FAT WU <wuwanfat () yahoo com hk>
Date: Wed, 4 Feb 2004 17:47:00 +0800 (CST)

Hi All,
 
   Can snort redirect packet or traffic to other
 computer?

My case is:   
Attacker->linux box(with snort)----Internal(computer A
and B)
 
   Suppose an attacker is to attack my linux box. Can
 I forward the attacker's traffic to computer A in my
 Intarnet? At the same time, normal traffic to
 computer B?

   As you know, I don't know the attacker's IP before
it
 attack. How can I redirect it? Do I need to read
 from the snort database? Can snort know how to
redirect? or Do I need to write some scripts?
 
   Many Thanks!
 
 Best,
 Fred
 
 

_________________________________________________________
必殺技、飲歌、小星星...
浪漫鈴聲  情心連繫
http://ringtone.yahoo.com.hk/


-------------------------------------------------------
The SF.Net email is sponsored by EclipseCon 2004
Premiere Conference on Open Tools Development and Integration
See the breadth of Eclipse activity. February 3-5 in Anaheim, CA.
http://www.eclipsecon.org/osdn
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: