Snort mailing list archives

Re: Virtualbox setting for snort


From: Giles Coochey <giles () coochey net>
Date: Tue, 09 Oct 2012 11:36:03 +0100

On 09/10/2012 11:16, Mitesh Jadia wrote:
Do you want to drop bad packets or just detect them?

If he wants to do that he would need to enable dot1q tagging to map to two VLANs to put the sensor Inline. It is possible with the latest version of Virtualbox, but his switch would need to support dot1q tagging as well.

In the host setup you would still just need a single adapter, but within the guest, configure the dot1q tags to create two interfaces.

http://en.wikipedia.org/wiki/IEEE_802.1Q


--
Regards,

Giles Coochey, CCNA, CCNAS
NetSecSpec Ltd
+44 (0) 7983 877438
http://www.coochey.net
http://www.netsecspec.co.uk
giles () coochey net


Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

------------------------------------------------------------------------------
Don't let slow site performance ruin your business. Deploy New Relic APM
Deploy New Relic app performance management and know exactly
what is happening inside your Ruby, Python, PHP, Java, and .NET app
Try New Relic at no cost today and get our sweet Data Nerd shirt too!
http://p.sf.net/sfu/newrelic-dev2dev
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: