[Snort-users] Hmmm.. Not setting promiscuous mode

Jones, Benny Ben at ...32...
Tue Jul 18 11:59:17 EDT 2000

Might there be some default filter that is active that's keeping you
from seeing traffic?

-----Original Message-----
From: David.Hoelzer at ...30... [mailto:David.Hoelzer at ...30...]
Sent: Tuesday, July 18, 2000 11:52 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] Hmmm.. Not setting promiscuous mode

Ok... I'm not new to snort or network sniffing by any means..  I haven't
used Snort since version 1.3 or so, so I
thought it was time to try out what's new.  The trouble is that it doesn't
set the interface into promiscuous mode for
some weird reason.  Yes, I'm running it as root, yes the adapter supports
Promisc mode (tcpdump works just fine).  What
the heck am I missing?

sample command line:

snort -i eth1 -v

The only packets that are captured are broadcasts and stuff directly to/from
the machine.

(Before you ask, let me settle a few more questions that I know I will see.
Yes, I'm sure there's traffic, No, it's not
plugged into a switch (note above, tcpdump works fine))


Snort-users mailing list
Snort-users at lists.sourceforge.net

More information about the Snort-users mailing list