Snort mailing list archives

Re: How to run multiple snort process on one system for monitoring multiple networks ?


From: "mdpeters" <michael.peters () lazarusalliance com>
Date: Mon, 27 Dec 2004 00:58:03 -0500

How to run multiple snort process on one system for monitoring multiple networks ?Just start up different 
configurations tailored for the network you have a sensor in. You will need to start a separate process for each 
additional configuration.

Something like this:

/opt/snort/bin/snort -c /opt/snort/etc/one.conf -i eth0 -l /var/log/snort-one -D
/opt/snort/bin/snort -c /opt/snort/etc/two.conf -i eth1 -l /var/log/snort-two -D
/opt/snort/bin/snort -c /opt/snort/etc/three.conf -i eth2 -l /var/log/snort-three -D

Regards,
Michael
  ----- Original Message ----- 
  From: Naveen.Pareek () iflexsolutions com 
  To: snort-users () lists sourceforge net 
  Sent: Monday, December 27, 2004 12:47 AM
  Subject: [Snort-users] How to run multiple snort process on one system for monitoring multiple networks ?





  Hi list,

  Can some one suggest me can we run 2 or 3 process of snort on one system to monitor different networks like DMZ, 
Internal and external from one system by installing multiple network cards on that system.

  Thanks

  NKP 



  DISCLAIMER:
  This message contains privileged and confidential information and is intended only for the individual named.If you 
are not the intended recipient you should not disseminate,distribute,store,print, copy or deliver this message.Please 
notify the sender immediately by e-mail if you have received this e-mail by mistake and delete this e-mail from your 
system.E-mail transmission cannot be guaranteed to be secure or error-free as information could be 
intercepted,corrupted,lost,destroyed,arrive late or incomplete or contain viruses.The sender therefore does not accept 
liability for any errors or omissions in the contents of this message which arise as a result of e-mail transmission. 
If verification is required please request a hard-copy version. 

Current thread: