Snort mailing list archives
RE: firewall and snort on the same machine
From: "John Berkers" <berjo () ozemail com au>
Date: Thu, 16 Aug 2001 18:07:53 +1000
I have a number of snort sensors at work with IPChains firewalls running on them. I block all traffic on eth0 (sensing interface) and most traffic on eth1 (admin interface) and I still see all the traffic. (RH 7.0, Kernel 2.2.19, Intel EEPRO100B/3Com 3c59x, Snort 1.7 - 1.8.1-rc2) How are you starting snort? If you use the -p option it will not put the card in promisc mode. Do you have a static IP? How have you specified the address in the conf file? You can use something like var HOME_NET $eth1_ADDRESS, but you do have to specify -i eth1 for this to work. Hope that helps you out. Regards John Berkers berjo () ozemail com au -----Original Message----- From: snort-users-admin () lists sourceforge net [mailto:snort-users-admin () lists sourceforge net]On Behalf Of Martijn Heemels Sent: Thursday, 16 August 2001 9:19 To: Snort-users () lists sourceforge net Subject: RE: [Snort-users] firewall and snort on the same machine [snip]
so you mileage may vary.
My mileage does vary... On my Linux 2.2 box with ipchains firewall and snort 1.8.1 (and previously 1.7 and up), snort only sees traffic that the firewall lets through... According to the snort FAQ (http://snort.sourcefire.com/docs/faq.html#4.3) this is supposed to happen. As a result i've seen some codered probes because i run apache but nothing more for months! In my logs I don't see the "eth1 has entered promiscuous mode" message that other people are reporting. How can I enable that option? Running Redhat 6.2 with all relevant patches. kernel 2.2.16-3 stock from redhat rpm. eth1 is a 3com 3C509 on a chello cablemodem Any tips are welcome! Martijn -- .: M. Heemels .:. webdesigner :. .: Eindhoven, NL, martijn () heemels com :. .: PGP of S/MIME encrypted e-mail preferred :. *** END PGP VERIFIED MESSAGE *** _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- firewall and snort on the same machine Mohr, Stefan (Aug 15)
- RE: firewall and snort on the same machine John Berkers (Aug 15)
- RE: firewall and snort on the same machine Martijn Heemels (Aug 15)
- RE: firewall and snort on the same machine Dragos Ruiu (Aug 15)
- RE: firewall and snort on the same machine John Berkers (Aug 16)
- RE: firewall and snort on the same machine Martijn Heemels (Aug 15)
- RE: firewall and snort on the same machine John Berkers (Aug 15)
