[Snort-users] Preventing Attacks

Slighter, Tim tslighter at ...5174...
Wed Jun 26 09:49:02 EDT 2002

could you setup port mirroring on a connected switch at the first point of
ingress past the firewall?

-----Original Message-----
From: Jeffrey Taylor [mailto:jeff at ...6176...]
Sent: Wednesday, June 26, 2002 9:14 AM
To: snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] Preventing Attacks

Is it possible to have Snort listen inside the firewall?  This is on a
one host set up.  I would like to see what is getting thru the
firewall, not what is thrown at the firewall.


Quoting McCammon, Keith <Keith.McCammon at ...3497...>:

> Please specify you OS, as well as your sensor placement relative to
> the target host and any firewalls.
> It would also help to specify what type of help you seek.  Do you
> want signature explanations?  Do you want to know if your hosts were
> compromised?  Do you want information on hardening your hosts?  Do you
> want to know how to reconfigure your firewall so that Snort doesn't
> get so much of this crap fired across her bow?

This sf.net email is sponsored by: Jabber Inc.
Don't miss the IM event of the season | Special offer for OSDN members! 
JabberConf 2002, Aug. 20-22, Keystone, CO http://www.jabberconf.com/osdn
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

More information about the Snort-users mailing list