Snort mailing list archives

RE: firewall and snort on the same machine


From: "John Berkers" <berjo () ozemail com au>
Date: Thu, 16 Aug 2001 18:07:53 +1000

I have a number of snort sensors at work with IPChains firewalls running on
them.  I block all traffic on eth0 (sensing interface) and most traffic on
eth1 (admin interface) and I still see all the traffic. (RH 7.0, Kernel
2.2.19, Intel EEPRO100B/3Com 3c59x, Snort 1.7 - 1.8.1-rc2)

How are you starting snort?  If you use the -p option it will not put the
card in promisc mode.

Do you have a static IP?  How have you specified the address in the conf
file?  You can use something like var HOME_NET $eth1_ADDRESS, but you do
have to specify -i eth1 for this to work.

Hope that helps you out.

Regards
John Berkers
berjo () ozemail com au


-----Original Message-----
From: snort-users-admin () lists sourceforge net
[mailto:snort-users-admin () lists sourceforge net]On Behalf Of Martijn
Heemels
Sent: Thursday, 16 August 2001 9:19
To: Snort-users () lists sourceforge net
Subject: RE: [Snort-users] firewall and snort on the same machine




[snip]
so you mileage may vary.


My mileage does vary...

On my Linux 2.2 box with ipchains firewall and snort 1.8.1 (and
previously 1.7 and up), snort only sees traffic that the firewall
lets through...
According to the snort FAQ
(http://snort.sourcefire.com/docs/faq.html#4.3) this is supposed to
happen.
As a result i've seen some codered probes because i run apache but
nothing more for months!

In my logs I don't see the "eth1 has entered promiscuous mode"
message that other people are reporting. How can I enable that
option?

Running Redhat 6.2 with all relevant patches.
kernel 2.2.16-3 stock from redhat rpm.
eth1 is a 3com 3C509 on a chello cablemodem

Any tips are welcome!

Martijn


--
.: M. Heemels .:. webdesigner :.
.: Eindhoven, NL, martijn () heemels com :.
.: PGP of S/MIME encrypted e-mail preferred :.



*** END PGP VERIFIED MESSAGE ***


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
http://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: