[Snort-users] snort behind firewall ??
jopperisano at ...1342...
Tue May 1 21:40:29 EDT 2001
-----BEGIN PGP SIGNED MESSAGE-----
OpenBSD 2.7 i386
IP Filter: v3.3.16
Snort Version 1.7
Default deny everything on xl1 (external NIC)
Running snort on xl1
Snort sees everything--I can actually see attacks reported by snort
in the alert file and then go find where IPF dropped the packet in
its log file.
- -----Original Message-----
From: Josh Oshiro [mailto:josh at ...155...]
Sent: Monday, April 30, 2001 2:13 PM
Cc: Robert D. Hughes; snort-users
Subject: Re: [Snort-users] snort behind firewall ??
It is up in the air right now wether or not snort can see packets
the firewall drop them. It seems it is system dependant. I would
to take a poll of who can snort through there firewall and who can't.
We'll need to know what kernal you are using, how it's configured,
firewall your using, how it's configures, and what os your using.
josh at ...155...
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:
-----BEGIN PGP SIGNATURE-----
Version: PGP 7.0.1
-----END PGP SIGNATURE-----
More information about the Snort-users