[Snort-users] no ip on interface?

Demetri Mouratis dmourati at ...3877...
Thu Sep 12 09:33:03 EDT 2002


I have just set up the same configuration as you describe below but also
including ACID.  The non-ip'd interface snorts just fine.

You can verify this for yourself by running snort -vde -i ethn.

HTH.
On Thu, 12 Sep 2002, T.Shaw wrote:

> Hello all..  this might be a stupid question.. but here goes..I have
> snort 1.8.7 up and running loggin to a pgsql database. I haven't
> installed ACID as of yet. I have configured snort to look at all traffic
> at an interface that currently doesnt have an ip assigned to it.
> Basically the interface is just up ( this is a linux box with two
> interfaces on it)  What im wondering is even tho i have no ip on the
> interface, will snort still be able to dump alerts and data into the
> database? Using a normal sniffer (ethereal, tcpdump) i can view the
> traffic on the interface by specifying the (usually) the -i parameter.
> If i gave snort a smiliar parameter.. everything should be fine correct?
> Would this screw up reporting and alerts?
>
> Thanks!
>
> Terrelle Shaw
>
>
> -------------------------------------------------------
> This sf.net email is sponsored by:ThinkGeek
> Welcome to geek heaven.
> http://thinkgeek.com/sf
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>

---------------------------------------------------------------------
Demetri Mouratis
dmourati at ...3878...





More information about the Snort-users mailing list