[Snort-users] FreeBSD + 2 devices + error OpenPcap

twig les twigles at ...131...
Thu Jul 25 14:38:02 EDT 2002


I'm going off of memory here but... I think that when
Free runs as a bridge (which you seem to be trying to
do) it needs to have berkeley packet filter compiled
into the kernel, but I thought that was there by
default so I may be confusing something.  I know that
you can either use the "options BRIDGE" in the kernel
or use the lkm "bridge.ko".

Have you looked at man 4 bridge yet?  It has a few
small caveats that may hang you up.

--- Éric Le Gallais <Eric at ...6453...> wrote:
> Hi,
> 
> i'm trying to get snort working on Freebsd with 2
> ethernet cards: xl0 and ep1.
> 
> These 2 ethernet cards don't have IP adresses.
> 
> I've tried ifconfig xl0 up and ifconfig ep1 up
> I've R(ead)TFM and a lot of other mailing lists.
> 
> When I start snort (snort -dev) I get this error:
> 
> ----
> Log directory = /usr/log/snort
> 
> Initializing Network Interface xl0
> ERROR: OpenPcap() device xl0 open:
> 	(no devices found) /dev/bpf0: Device not configured
> Fatal Error: Quitting...
> ----
> 
> the device /dev/bpf0 does exists.
> 
> Does anyone has any idea?
> 
> Éric 
> 
> 
> 
>
-------------------------------------------------------
> This sf.net email is sponsored by: Jabber - The
> world's fastest growing
> real-time communications platform! Don't just IM.
> Build it in!
> http://www.jabber.com/osdn/xim
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or
> unsubscribe:
>
https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
>
http://www.geocrawler.com/redir-sf.php3?list=snort-users


=====
-----------------------------------------------------------
All warfare is based on deception.
-----------------------------------------------------------

__________________________________________________
Do You Yahoo!?
Yahoo! Health - Feel better, live better
http://health.yahoo.com




More information about the Snort-users mailing list