[Snort-users] Win32 Port of Snort
Keith.McCammon at ...3497...
Mon May 20 13:28:04 EDT 2002
Not sure about 1, but as far as 2 is concerned, just deactivate (un-check) TCP/IP on your monitoring interface within the network connection properties.
From: Michael J Worden [mailto:mjworden at ...2784...]
Sent: Monday, May 20, 2002 4:04 PM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] Win32 Port of Snort
I'm in the process of comparing the functionality of Snort for Win32 (on
Windows 2000) with the versions I've been running on Linux for some time.
I'm finding Snort on Win32 almost useable with a few exceptions (of course,
I'm just getting started...):
My two big questions are:
1) Is the ability to run as a service lost in the current version? In the
faq, this has been added as of snort-1.6.3-patch2. But the '-I' switch is
now allocated to a different function. (Yes, I know about the 'srvany.exe'
option. I've not had great experiences with srvany, and would like to
2) Is there an option to forego the IP address on a Windows 2000
interface? I'd like to avoid having my promiscuous mode adapter being
Thanks in advance...
Don't miss the 2002 Sprint PCS Application Developer's Conference
August 25-28 in Las Vegas -- http://devcon.sprintpcs.com/adp/index.cfm
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:
More information about the Snort-users