[Snort-users] Winpcap and cheap NICs...
tobias at ...8088...
Sat Jan 25 21:26:03 EST 2003
I'm not really sure what you mean. This is a fresh install, so it wouldn't
be using the old name. Take a look at this:
database: sensor name = MACHINENAME:\Device\Packet_NdisWanIp
database: sensor id = 1
This is what is get when I start Snort on the new machine.
This is what I'm used to seeing on my other sensors:
database: sensor name =
database: sensor id = 2
Thanks once again!
From: John [mailto:john at ...5978...]
Sent: Saturday, January 25, 2003 8:27 PM
To: Tobias Rice
Subject: Re: [Snort-users] Winpcap and cheap NICs...
your interface name is probably different now...
On Sat, Jan 25, 2003 at 06:20:28PM -0800, Tobias Rice wrote:
> From: "Tobias Rice" <tobias at ...8088...>
> To: <snort-users at lists.sourceforge.net>
> X-MDRemoteIP: 126.96.36.199
> X-Return-Path: tobias at ...8088...
> X-MDaemon-Deliver-To: snort-users at lists.sourceforge.net
> Subject: [Snort-users] Winpcap and cheap NICs...
> Errors-To: snort-users-admin at lists.sourceforge.net
> X-Original-Date: Sat, 25 Jan 2003 18:20:28 -0800
> Date: Sat, 25 Jan 2003 18:20:28 -0800
> I recently replaced my server's mainboard and CPU. It came with an onboard
> NIC, so I removed the 3Com. I then reloaded the OS and Snort. Snort starts
> up just fine like normal, but when I attack the machine, I never get an
> alert. Is it possible that Winpcap doesn't work on cheap NICs? I'm pretty
> sure that I have everything setup correctly, as I have setup Snort many
> times successfully. Any suggestions would be greatly appreciated.
> Many thanks!
> This SF.NET email is sponsored by:
> SourceForge Enterprise Edition + IBM + LinuxWorld = Something 2 See!
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> Snort-users list archive:
john at ...5978...
fingerprint: 7A96 24BE F9B1 1092 B4F6 B53D 1DB4 139B F217 DE50
More information about the Snort-users