[Snort-users] snort ignores ppp0

centipede centiped at ...1832...
Sun Apr 15 13:09:45 EDT 2001


Nope... it doesn't... I tried it.
snort is just in love with my eth0.
and it believes in monogamy...
unfortunately... ;-)

centipede.

Fyodor wrote:

> You should be running snort on interface ppp0, and your HOME_NET should
> be set to $ppp0_ADDRESS at the same time, does it work? :)
> 
> On Sun, Apr 15, 2001 at 04:01:32PM +0300, centipede wrote:
> 
>> Hi.
>> 
>> I've just initially installed snort.  the problem is that it detects 
>> intrusions only on my eth0
>> while utterly ignoring ppp0, which is, naturally, the only interface I 
>> really care to have a
>> NIDS on.
>> I tried switching between "-i eth0" and "-i ppp0" and between HOME_NET 
>> 192.168.1.0/24
>> to HOME_NET $ppp0_ADDRESS but snort insisted on letting every ppp0 
>> packet slip
>> in innoticed.
>> I even tried using the "-i any" but it didn't work.  ipchains was of 
>> course suspended during
>> the tests and EXTERNAL_NET was set to "any" all the time.
>> 
>> any suggestions ?
>> 
>> thanks.
>> 
>> 
>> _______________________________________________
>> Snort-users mailing list
>> Snort-users at lists.sourceforge.net
>> Go to this URL to change user options or unsubscribe:
>> http://lists.sourceforge.net/lists/listinfo/snort-users
>> Snort-users list archive:
>> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>> 





More information about the Snort-users mailing list