[Snort-users] Hmmm.. Not setting promiscuous mode

David.Hoelzer at ...30... David.Hoelzer at ...30...
Tue Jul 18 12:04:19 EDT 2000


No, I'm running it with no filters.  Checking ifconfig shows that PROMISC is NOT set.




"Jones, Benny" <Ben at ...32...> on 07/18/2000 11:59:17 AM

To:   David Hoelzer/SMC at ...34..., snort-users at lists.sourceforge.net
cc:

Subject:  RE: [Snort-users] Hmmm.. Not setting promiscuous mode




Might there be some default filter that is active that's keeping you
from seeing traffic?

-----Original Message-----
From: David.Hoelzer at ...30... [mailto:David.Hoelzer at ...30...]
Sent: Tuesday, July 18, 2000 11:52 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] Hmmm.. Not setting promiscuous mode




Ok... I'm not new to snort or network sniffing by any means..  I haven't
used Snort since version 1.3 or so, so I
thought it was time to try out what's new.  The trouble is that it doesn't
set the interface into promiscuous mode for
some weird reason.  Yes, I'm running it as root, yes the adapter supports
Promisc mode (tcpdump works just fine).  What
the heck am I missing?


sample command line:

snort -i eth1 -v


The only packets that are captured are broadcasts and stuff directly to/from
the machine.

(Before you ask, let me settle a few more questions that I know I will see.
Yes, I'm sure there's traffic, No, it's not
plugged into a switch (note above, tcpdump works fine))

Thanks!



_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
http://lists.sourceforge.net/mailman/listinfo/snort-users

_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
http://lists.sourceforge.net/mailman/listinfo/snort-users






More information about the Snort-users mailing list