[Snort-users] Hmmm.. Not setting promiscuous mode

Martin Roesch roesch at ...1...
Tue Jul 18 12:06:04 EDT 2000


What OS are you running on?  Can you do an 'ifconfig -a' and see if the
interface is in promiscuous mode?

    -Marty

David.Hoelzer at ...30... wrote:
> 
> Ok... I'm not new to snort or network sniffing by any means..  I haven't used Snort since version 1.3 or so, so I
> thought it was time to try out what's new.  The trouble is that it doesn't set the interface into promiscuous mode for
> some weird reason.  Yes, I'm running it as root, yes the adapter supports Promisc mode (tcpdump works just fine).  What
> the heck am I missing?
> 
> sample command line:
> 
> snort -i eth1 -v
> 
> The only packets that are captured are broadcasts and stuff directly to/from the machine.
> 
> (Before you ask, let me settle a few more questions that I know I will see.  Yes, I'm sure there's traffic, No, it's not
> plugged into a switch (note above, tcpdump works fine))
> 
> Thanks!
> 
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> http://lists.sourceforge.net/mailman/listinfo/snort-users

-- 
Martin Roesch                      <roesch at ...2...>
Core R&D                         http://www.hiverworld.com
Hiverworld, Inc.       Continuous Adaptive Risk Management




More information about the Snort-users mailing list