Snort mailing list archives

ssh-tunnel between sensor and database-server


From: Steffen "Maetzky (extern)" <estm () gedas de>
Date: 25 Aug 2004 17:47:02 +0200

I have build an ssh-tunnel between my snort-sensor and my
database-server and it seems to work.

I had like to control this with tcpdump and it shows something like
this:

        "IP1".32817 > "IP2".22 
        "IP2".22 > "IP1".32817

        "IP1"=sensor
        "IP2"=server

I expect port 3306 instead of 32817 and that confuses me.

Can anyone explain me why 32817 is used?
Does ssh "hide" the source-port by using it?

Thanks in advance,

Steffen 



-------------------------------------------------------
SF.Net email is sponsored by Shop4tech.com-Lowest price on Blank Media
100pk Sonic DVD-R 4x for only $29 -100pk Sonic DVD+R for only $33
Save 50% off Retail on Ink & Toner - Free Shipping and Free Gift.
http://www.shop4tech.com/z/Inkjet_Cartridges/9_108_r285
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: