Snort mailing list archives

Re: Linux Snort Stealth Interface Help Request


From: Chris Green <cmg () sourcefire com>
Date: Thu, 21 Mar 2002 18:33:54 -0500

"Mark Gannon" <markgannon () rcsis com> writes:

Hello,

I'm having difficulty implementing a stealth inteface per Snort FAQs 3.1 and

3.2 on a Linux (SuSE 7.3 with kernel 2.4.14) system using a regular straight

through cable.   I start snort and no traffic is displayed to stdout even 
though another interface on the same segment shows traffic via tcpdump. 

Eth1 is connected to a Netgear Dual Speed Hub (DS 106) that has a link light


Is the traffic that you are monitoring at 10 or 100. You can't do
both. I really wish the Netgear 100bt-only hub was more popular
because thats the most common problem.
-- 
Chris Green <cmg () sourcefire com>
Eschew obfuscation.


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: