[Snort-users] Snort startup error
Rense at ...1620...
Wed Mar 21 07:49:37 EST 2001
Thx all, it worked, I totaly forgot to test that.
From: Steve Loughran [mailto:stevelsnort at ...1465...]
Sent: Wednesday, March 21, 2001 1:04 PM
To: Rense Buijen; snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] Snort startup error
Have you tried it with just:
var HOME_NET 192.168.25.99/32
(No quotes around the address)
----- Original Message -----
From: "Rense Buijen" <Rense at ...1620...>
To: <snort-users at lists.sourceforge.net>
Sent: Wednesday, March 21, 2001 11:09 AM
Subject: [Snort-users] Snort startup error
> Hello all,
> I am testing something with snort, this is the first time I am using this
> I installed it and when I try to run the command: /usr/sbin/snort -u snort
> -g snort -s -d -i eth0 -l /var/log/snort -c /etc/snort/snort.conf
> The following error gets displayed:
> --== Initializing Snort ==--
> Initializing Network Interface eth0
> Decoding Ethernet on interface eth0
> Initializing Preprocessors!
> Initializing Plug-ins!
> Initializating Output Plugins!
> Initializing rule chains...
> Kernel filter, protocol ALL, raw packet socket
> ERROR /etc/snort/snort.conf (7) => Rule IP addr ("192.168.25.99") didn't
> x-late, WTF?
> This what my configfile looks like:
> var HOME_NET "192.168.25.99"/32
> var EXTERNAL_NET any
> var DNS_SERVERS [192.168.25.3/32,18.104.22.168/32,10.11.202.26/32]
> preprocessor defrag
> preprocessor http_decode: 80 8080
> preprocessor portscan: $HOME_NET 4 3 /var/log/snort/portscan.log
> preprocessor portscan-ignorehosts: $DNS_SERVERS
> -- snip ---
> Can someone explain to me why I get that error, I tryed to change
> "192.168.25.99"/32 into "192.168.25.99/32" but it doesnt work.
> With regards,
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> Snort-users list archive:
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:
More information about the Snort-users