Snort mailing list archives

Re: Any issues with dup packets on snort?


From: Jason Haar <Jason.Haar () trimble co nz>
Date: Thu, 01 Dec 2005 07:57:24 +1300

Richard Bejtlich wrote:
If your system is configured as I think it is, you should only see
duplicates for intra-switch traffic.  Is that the case?
  
Yes - that about sums it up. We're monitoring traffic entering the LAN,
and transiting between WAN links. So you can see LAN traffic twice.

So my only concern is that this situation might somehow lead to snort
getting "confused". If that isn't the case, then I'd be happy to live
with it.

-- 
Cheers

Jason Haar
Information Security Manager, Trimble Navigation Ltd.
Phone: +64 3 9635 377 Fax: +64 3 9635 417
PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1



-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems?  Stop!  Download the new AJAX search engine that makes
searching your log files as easy as surfing the  web.  DOWNLOAD SPLUNK!
http://ads.osdn.com/?ad_id=7637&alloc_id=16865&op=click
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: