[Snort-users] please help with solaris problem
fygrave at ...121...
Thu Nov 9 06:25:50 EST 2000
On Wed, Nov 08, 2000 at 10:00:17AM -0800, loki at ...765... wrote:
> Attn fellow snorters--
> Need help with the following problem. Maybe someone can clarify for me..
> I have a Solaris machine with 2 interfaces on it.
> hme0 => 192.168.X.X
> hme1 => 0.0.0.0 (actual ip)
> I have installed snort to replace what is currently being used, ISS
> RealSecure. RealSecure was binding to hme1 (0.0.0.0), which this interface
> is in promisc. mode. In my snort-lib file, I am specifying for my home_net
> to be 0.0.0.0/24 .... is this correct?
no, it should be the actual ip/netmask of a network you want to 'protect'. if
you want to apply the rule (or ruleset) to any ip address use either any or 0.0.0.0/0 ip/mask.
More information about the Snort-users