Snort mailing list archives

Snort on Multiple Interfaces


From: Ron <iago () valhallalegends com>
Date: Thu, 21 Jul 2005 15:45:55 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hey guys,

I am running snort on a computer that bridges my network.  All traffic
from the internet enters through eth0, which bridges it to eth1, which
plugs into a switch.

2 questions:
- - Should I run Snort on both interfaces, or just one? If just one, which
is better, internal or external?
- - Should I run Snort in permiscuous mode?  I don't see any reason to,
since neither side has a hub, but I'm just checking to make sure.

Thanks!
Ron
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.9.15 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFC4AmDfqSf2EkP4p4RArteAJ0cVWmEy2BJX+2+yOEQfqYN7rhqnwCfcTTH
/NG/1IHcV6NXD3bp3O7tNJU=
=n9uJ
-----END PGP SIGNATURE-----


-------------------------------------------------------
SF.Net email is sponsored by: Discover Easy Linux Migration Strategies
from IBM. Find simple to follow Roadmaps, straightforward articles,
informative Webcasts and more! Get everything you need to get up to
speed, fast. http://ads.osdn.com/?ad_id=7477&alloc_id=16492&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: