[Snort-users] Setting snort interface to "listen only"

Joe Lawson jlawson at ...1875...
Mon Apr 23 09:00:10 EDT 2001


All:

I've got a Windows 2000 box running the Win32 version of snort.  I'd like to
set the public interface (outside firewall) to listen only and have a
private interface inside the firewall that will log to a syslog daemon.
I've read that it is possible to not assign an IP address to the interface
and still pick up packets on the wire.  I've tried to unbind the IP address
from the NIC and it doesn't appear to work.  Is there another way to
accomplish this and if so what is it?

TIA.

Joe Lawson







More information about the Snort-users mailing list