[Snort-users] Alert Leak?

joseph.warner at ...6725... joseph.warner at ...6725...
Wed Jan 29 09:22:09 EST 2003


I have a PC with two NIC cards, one configured for my internal network
and the other for my T1 connection.  I'm using ZoneAlarm to protect
the NIC/connection using the T1.  I have snort running on our internal
network and sometimes it generates alerts for activity that's being
blocked by ZoneAlarm on the external (T1) NIC.  How is this possible
since traffic isn't routable between the two NIC cards?  How is snort
able to see this traffic at all?


This message and any included attachments are from Siemens Medical Solutions 
Health Services Corporation and are intended only for the addressee(s).  
The information contained herein may include trade secrets or privileged or 
otherwise confidential information.  Unauthorized review, forwarding, printing, 
copying, distributing, or using such information is strictly prohibited and may 
be unlawful.  If you received this message in error, or have reason to believe 
you are not authorized to receive it, please promptly delete this message and 
notify the sender by e-mail with a copy to CSOffice at ...6726...  Thank you

More information about the Snort-users mailing list