[Snort-users] Promiscuous monitoring

Jason Gauthier jgauthier at ...6155...
Tue Jul 2 05:04:06 EDT 2002

My first thought is that the EXTERNAL_NET variable isn't set right.
Is that assigned as "any"?

-----Original Message-----
From: Eric Ferguson [mailto:eric.ferguson at ...6215...]
Sent: Tuesday, July 02, 2002 7:06 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] Promiscuous monitoring

I have Snort 1.8.6 running on Red Hat 7.3 with ACID and MySQL.  I start
Snort with the -v option to verify that Snort is seeing traffic and all
seems well.  My only problem is that attacks (ones I generate myself) are
only logged if directed at the Snort IP address.  If I direct an attack to
another machine on the same subnet, Snort does not identify the attack (yes
I am running a hub and not a switch...:-)).  Sounds like something simple to
me, I am just not sure what it is.




Eric Ferguson - NNCSE

4440 Embassy Drive

Sykesville, Md. 21784

phone: 410-876-0585

cell: 443-677-6119

email: eric.ferguson at ...6215...


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20020702/19e3c9da/attachment.html>

More information about the Snort-users mailing list