Snort mailing list archives
Ipchains questions
From: Darrin Powell <dpowell () lssi net>
Date: Fri, 24 Aug 2001 17:12:04 -0400
Ok here is my scenario I have a box outside the firewall with a deny all ipchians approach running snort. If I scan that box snort picks it up. In my snort rules I have multiple ip address that I want snort to monitor. var HOME_NET [111.111.111.112,111.111.111.113,111.111.111.114] The rest of the configuration is pretty much default for snort-1.8p1-0. Other than location of rules and conf file. These other machines have ipchains as well with a deny all approach. If I scan any of those boxes snort does not pick it up. Should snort pick up these other machines or do I have to change my ichains so they can see eachother? Thanks in advance Darrin _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: http://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Ipchains questions Darrin Powell (Aug 24)
- Re: Ipchains questions Blake Frantz (Aug 24)
- Re: Ipchains questions Darrin Powell (Aug 27)
- Re: Ipchains questions Blake Frantz (Aug 27)
- Re: Ipchains questions Darrin Powell (Aug 27)
- <Possible follow-ups>
- RE: Ipchains questions Ciaron Gogarty (Aug 27)
- Re: Ipchains questions Darrin Powell (Aug 28)
- RE: Ipchains questions Mayers, Philip J (Aug 28)
- Re: Ipchains questions Borja Marcos (Aug 28)
- Re: Ipchains questions Darrin Powell (Aug 28)
- Re: Ipchains questions Blake Frantz (Aug 24)
