Snort mailing list archives

Re: Use dyndns to ignore my ip


From: waldo kitty <wkitty42 () windstream net>
Date: Sat, 16 Feb 2013 00:17:02 -0500

On 2/15/2013 23:19, Jeremy Hoel wrote:
Ahh.. but you might be assuming that the server/snort ip changes..
what if it doesn't but the outside of the router/gateway does..  :-)

then that would not be indicated in the snort.conf and thus would not apply to 
the snort installation on the interior network... at least in my experiences ;)

On Fri, Feb 15, 2013 at 9:08 PM, waldo kitty<wkitty42 () windstream net>  wrote:
On 2/15/2013 14:33, Jeremy Hoel wrote:
yeah..  a crontab that checks the dyn dns entry once a minute and also
checkes $HOME_NET and if it doesn't contain the dyn dns address,
rewrite home_net (using sed or something) and then restart snort.

I'd be curious if you knew how often your outside Ip changed.  you
could bump the script up to check every 5 minutes or so if you
wheren't that worried.

ain't that hard to do if one simply handles it in their connection scripts with
an include file for those vars :)



------------------------------------------------------------------------------
The Go Parallel Website, sponsored by Intel - in partnership with Geeknet, 
is your hub for all things parallel software development, from weekly thought 
leadership blogs to news, videos, case studies, tutorials, tech docs, 
whitepapers, evaluation guides, and opinion stories. Check out the most 
recent posts - join the conversation now. http://goparallel.sourceforge.net/
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: