[Snort-users] interface on promiscuous mode ?

Ashley Thomas athomas at ...3539...
Fri Mar 22 11:12:50 EST 2002


hi,

i am setting up snort on a linux machine and needs the ethernet interface
to be in stealth mode.

so i did a simple "ifconfig eth0 up"

and see the ifconfig -a as:

eth1      Link encap:Ethernet  HWaddr 00:03:86:45:BB:77
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:1029434 errors:0 dropped:0 overruns:0 frame:0
          TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100
          Interrupt:5 Memory:f9000000-f9020000


But i see only arp and broadcast packets when i do a tcpdump -i eth1

Looking at /var/log/messages, i don't see "device eth1 entered promiscuous
mode"

Is this the problem ? How do i make it go into promiscuous mode ?

thanks






More information about the Snort-users mailing list