[Snort-users] please help with solaris problem

Fyodor fygrave at ...121...
Thu Nov 9 06:25:50 EST 2000

On Wed, Nov 08, 2000 at 10:00:17AM -0800, loki at ...765... wrote:
> Attn fellow snorters--
> Need help with the following problem. Maybe someone can clarify for me.. 
> I have a Solaris machine with 2 interfaces on it.
> hme0 => 192.168.X.X
> hme1 => (actual ip)
> I have installed snort to replace what is currently being used, ISS
> RealSecure. RealSecure was binding to hme1 (, which this interface
> is in promisc. mode. In my snort-lib file, I am specifying for my home_net
> to be  .... is this correct?

 no, it should be the actual ip/netmask of a network you want to 'protect'. if
 you want to apply the rule  (or ruleset) to any ip address use either any or ip/mask. 

More information about the Snort-users mailing list