[Snort-users] Multi nic host?
Steve.Shockley at ...378...
Thu Sep 7 14:42:21 EDT 2000
One problem you may run into here is that your switch doesn't route by IP
address, it routes by hardware (MAC) address. A possible solution here
would be to run without IP addresses on at least three of them.
In my configuration, my entire network is switched, so it's unfeasible to
monitor the entire network. I'm mostly concerned with traffic going in and
out of the firewall and over the frame-relay link to our global offices
(which I don't control). So, I set up a small hub (repeater, not switch)
with four machines plugged into it; the firewall's Inside port, the FR
router, the IDS machine, and the switches. That way the IDS sees all the
traffic going in or out of my office.
Most likely a silly question but here goe's. Can snort support a multi nic
machine? Lets say I have a private network 10.1.1.0 over four 24 port hubs
all connected by one switch.. Because the switch does some routing I can
not just plug into the switch a catch all the traffic. What if I had a
machine with four nics, one for each hub, for example nic 1 10.1.1.11, nic
2 10.1.1.12 and so on.. Then set
-h 10.1.1.0/24. Would snort analyze all the traffic on each NIC?
-----BEGIN PGP PUBLIC KEY BLOCK-----
-----END PGP PUBLIC KEY BLOCK-----
Snort-users mailing list
Snort-users at lists.sourceforge.net
More information about the Snort-users