[Snort-users] please help with solaris problem

Fyodor fygrave at ...121...
Thu Nov 9 06:25:50 EST 2000


On Wed, Nov 08, 2000 at 10:00:17AM -0800, loki at ...765... wrote:
> 
> Attn fellow snorters--
> 
> Need help with the following problem. Maybe someone can clarify for me.. 
> I have a Solaris machine with 2 interfaces on it.
> 
> hme0 => 192.168.X.X
> hme1 => 0.0.0.0 (actual ip)
> 
> I have installed snort to replace what is currently being used, ISS
> RealSecure. RealSecure was binding to hme1 (0.0.0.0), which this interface
> is in promisc. mode. In my snort-lib file, I am specifying for my home_net
> to be 0.0.0.0/24  .... is this correct?
> 

 no, it should be the actual ip/netmask of a network you want to 'protect'. if
 you want to apply the rule  (or ruleset) to any ip address use either any or 0.0.0.0/0 ip/mask. 



More information about the Snort-users mailing list