[Snort-users] not sure if I have this right

Wed Jul 31 08:38:08 EDT 2002

OK just for testing, use the following rule at the end of your snort.conf
file and ping to the host where snort is running (from some other machine)

alert icmp any any -> any any (msg: "ICMP ping packet";)

This will create alerts. Don't use this rule forever, this is bad!


I set up snort the other day and I was wondering how I could go about
testing it.

So far it hasn't logged anything, which might be good news, but it also
might mean that I borked the setup.

Here is what I have:

snort 1.8.7 on the same box as my iptables based firewall. (Just out of
interest, will this tell me everything that is coming into the system or
just what gets past the firewall?)

Here is the network setup part of the conf:


And here is the logging portion:

output alert_syslog: LOG_AUTH LOG_ALERT

Now, I don't use syslogd but metalog. However, as I understand it,
metalog is supposed to mimic the functionality of syslog and the
iptables logging works.

Can anyone see anything obvious that I have done wrong here, or is my
system just being graciously ignored at the moment :)

