Snort mailing list archives
RE: Home-Net, and so on!
From: "Wirth, Jeff" <WirthJe () DNB com>
Date: Thu, 28 Mar 2002 10:08:51 -0500
Whats with that Home_net in the starting option -h home net and that home net in the conf files?
Using the "-h <ip address/network>" will override your snort.conf "HOME_NET" variable. Also the "-h" option is useful if you're running snort without "-c" (No snort.conf).
But I could not get Snort to start whatever I did to enter the Netmask.
Snort is looking for IP/Net in CIDR notation. i.e. 192.168.1.0/24. Based on your information, I would guess you are using a 192.168.0.0 address space for you private network. Your entry of 192.168.48.1/5 looks a bit odd. Is your internal network 192.168.48.0? If so the correct CIDR notation would be 192.168.48.0/24.
Plus, Home_net in the conffiles, what does it mean? Is it the net I want to defend? Like 192.168.48.1/5 or is it the Ip I'm in the internet with?
I am guessing that you have a firewall/NAT device doing ppp to the internet. If this is the case you will what to have snort snorting on your interface/ip address on the public side (internet). It would be helpful if you gave a general description of how your network is laid out... Hope this helps, - Jeff _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Home-Net, and so on! Fritjof Heyde (Mar 27)
- <Possible follow-ups>
- RE: Home-Net, and so on! Wirth, Jeff (Mar 28)
