[Snort-users] snortsam

Ralf Hildebrandt Ralf.Hildebrandt at ...3909...
Wed May 15 05:22:02 EDT 2002


I'm trying out to run snort together with snortsam and the snort-alert

After a painful installation process due to the lousy docs, I now have
the follwoing problem:

When I start snort, I get:

Back Orifice detection brute force: DISABLED
Using LOCAL time
[Alert_FWsam] Connected to mgmt station
[Alert_FWsam](CheckIn) Password mismatch! Ignoring mgmt station
1086 Snort rules read...
1086 Option Chains linked into 109 Chain Headers
0 Dynamic rules
-*> Snort! <*-
Version 1.8.7beta1 (Build 117)

What the hell is going on?
In my snortsam.conf:


In my snort.conf:

output alert_fwsam:

Clearly, those two passwords match.

Snort is started like this:
 /usr/sbin/snort -S
-h,,, -c
/etc/snort/snort.conf -l /var/log/snort -b -d -u snort -g snort -i eth1

