Snort mailing list archives

Re: snort daemon to listen to eth2 and eth3 in promiscuous mode


From: Kaushal Shriyan <kaushalshriyan () gmail com>
Date: Tue, 19 Feb 2013 17:59:31 +0530

On Tue, Feb 19, 2013 at 5:54 PM, Ayodele Okeowo <aymacro () gmail com> wrote:

What command do you type when running snort in inline? You will have to
pair both interfaces in order to use both for sniffing.

Paste your command on here and let's see. :)

Ayo


Thanks Ayo for the quick reply and i start snort using init script on
CentOS 5.8 with the below mentioned details

[root@snort ~]# /etc/init.d/snortd status
snort (pid 17573) is running...
[root@snort ~]# ps aux | grep snort
snort    17573  0.0  0.2 417000 71064 ?        Ssl  17:21   0:00
/usr/sbin/snort -A fast -b -d -D -i eth2 -u snort -g snort -c
/etc/snort/snort.conf -l /var/log/snort
root     17647  0.0  0.0  61172   752 pts/0    S+   17:58   0:00 grep snort
[root@snort ~]#

Regards

Kaushal
------------------------------------------------------------------------------
Everyone hates slow websites. So do we.
Make your web apps faster with AppDynamics
Download AppDynamics Lite for free today:
http://p.sf.net/sfu/appdyn_d2d_feb
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: