Snort mailing list archives

Re: I can not see it


From: "Michael Scheidell" <scheidell () secnap net>
Date: Fri, 6 Oct 2006 19:50:32 -0400

doesn't look like a snort problem.
 
read the FAQ's about switches, hubs, and network taps.
 
 

        -----Original Message-----
        From: snort-users-bounces () lists sourceforge net
[mailto:snort-users-bounces () lists sourceforge net] On Behalf Of
Greta.Ji () sungard com
        Sent: Tuesday, October 03, 2006 2:27 PM
        To: Snort-users () lists sourceforge net
        Subject: [Snort-users] I can not see it
        
        
        Hi, 
         
        I am a new user on this list. I have a simple problem, and hope
to get a 
        help. I just installed Snort 2.6 on Centos. I follow the
document to bring 
        eth1 up (eth0 has IP to connect to the Internal network).  But I
can not 
        see any traffic on eth1 (tcpdump -i eth1). I checked the switch,
I can see
        traffice on the interface (# sh interface f0/8):
         
            monitor session 1 source interface Fa0/2
            monitor session 1 destination interface Fa0/8
        
             270471 packets output, 65224246 bytes, 0 underruns
         
         
        Did I missing anything at here? Could some one help me?
         
        Thank you,
         
        --Greta

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
opinions on IT & business topics through brief surveys -- and earn cash
http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: