Snort mailing list archives

RE: NEWBIE: Snort


From: "Atkins, Dwane P" <ATKINSD () uthscsa edu>
Date: Wed, 16 Jun 2004 10:19:50 -0500

I heard that my last posting was hard to read.

_____________________________________________ 
From:         Atkins, Dwane P  
Sent: Wednesday, June 16, 2004 8:47 AM
To:   'snort-users () lists sourceforge net'
Subject:      NEWBIE: Snort

I have set up Snort on Redhat 9.0 per Patrick Harper's document.  It
all seem to set up just fine, but when we did attacks, it would not
report on the ACID web page.  I have two NICs.  One is a 3C509B
EtherlinkIII and the other is a 3C905CX-TXM.  I would like the second
one to do our sniffing and use the first as a management port.  I
guess this is a three part question.  What would I do to make sure the
3C905 is the sniffing port?  How would I make sure that each time it
is rebooted, it comes up in promiscuous mode?  Also, what can I test
to see the counters on my ACID web page increment? 

Thank you

Dwane

Current thread: