[Snort-users] Promiscuous monitoring

Eric Ferguson eric.ferguson at ...6215...
Tue Jul 2 04:07:21 EDT 2002


I have Snort 1.8.6 running on Red Hat 7.3 with ACID and MySQL.  I start
Snort with the -v option to verify that Snort is seeing traffic and all
seems well.  My only problem is that attacks (ones I generate myself)
are only logged if directed at the Snort IP address.  If I direct an
attack to another machine on the same subnet, Snort does not identify
the attack (yes I am running a hub and not a switch.:-)).  Sounds like
something simple to me, I am just not sure what it is.

 

Thanks,

 

Eric Ferguson - NNCSE

4440 Embassy Drive

Sykesville, Md. 21784

phone: 410-876-0585

cell: 443-677-6119

email: eric.ferguson at ...6215...

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20020702/7414fa55/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: Eric V Ferguson (eric.ferguson at ...6215...).vcf
Type: text/x-vcard
Size: 459 bytes
Desc: not available
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20020702/7414fa55/attachment.vcf>


More information about the Snort-users mailing list