[Snort-users] snort and nmap

Andreas Hasenack andreas at ...1574...
Thu Oct 4 07:17:16 EDT 2001


Em Wed, Oct 03, 2001 at 06:08:45PM -0700, Rob Collins escreveu:
> I've got snort on a box with nmap.  while running
> 'snort -vd -i lo' I also run 'nmap -sT 127.0.0.1';
> this works fine and I see some 900 tcp packets fly by.
>  But while running 'snort -vd -l eth0' and running
> 'nmap -sT 192.168.1.5' (which is the valid eth0 ip
> address), I see no tcp packets at all.  What is
> happening?

The kernel will notice that this address is local, you
won't see these packtes on eth0.





More information about the Snort-users mailing list