Snort mailing list archives

NEWBIE: Snort


From: "Atkins, Dwane P" <ATKINSD () uthscsa edu>
Date: Wed, 16 Jun 2004 08:47:11 -0500

I have set up Snort on Redhat 9.0 per Patrick Harper's document.  It all
seem to set up just fine, but when we did attacks, it would not report
on the ACID web page.  I have two NICs.  One is a 3C509B EtherlinkIII
and the other is a 3C905CX-TXM.  I would like the second one to do our
sniffing and use the first as a management port.  I guess this is a
three part question.  What would I do to make sure the 3C905 is the
sniffing port?  How would I make sure that each time it is rebooted, it
comes up in promiscuous mode?  Also, what can I test to see the counters
on my ACID web page increment? 

Thank you

Dwane

Current thread: