If you are simply NATing one IP and you have snort listening on your
outside (public) interface, snort will see all traffic with respect to the
IP of that interface.  If you have snort listen on your inside
(private) interface, snort will pick up the NAT'ed traffic -- which will
allow you to determine which box the traffic is really comming/going

Snort will see the same traffic, but the ingress destination and egress
source will be different depending on which interface you have it
listening on.

To answer your question; if your snort box is also your firewall then yes
your assumption is correct.  Disallowed traffic will be discarded before
it ever reaches the inside interface (for inbound traffic), thus snort
will not see this traffic unless it is listening on the outside interface.

Hope this helps.
(if any of this seems bass ackwards...I'm blaming it on the NyQuil)


