[Snort-users] Snort with DHCP

Sadanapalli, Pradeep Kumar (MED, TCS) Pradeep.Sadanapalli at ...8430...
Fri May 2 13:29:27 EDT 2003


Thanks Erek. Yes my listening interface is eth0. My intention is to
configure snort to see the traffic only on my NIC.
So by keeping "var HOME_NET $eth0-ADDRESS" in snort.conf, will it meet
my requirement? What is the difference between 
running snort in promiscuous mode and not in promiscuous mode?  

Thanks
Pradeep


-----Original Message-----
From: David Alonso De La Vega Tapage [mailto:delavegad at ...7768...]
Sent: Friday, May 02, 2003 1:44 PM
To: Erek Adams
Cc: Sadanapalli, Pradeep Kumar (MED, TCS);
snort-users at lists.sourceforge.net
Subject: Re: [Snort-users] Snort with DHCP




Erek Adams wrote:

>On Fri, 2 May 2003, Sadanapalli, Pradeep Kumar (MED, TCS) wrote:
>  
>
>
>If your listening interface is eth0 then define it like:
>
>	var HOME_NET $eth0_ADDRESS
>
>  
>
if you eth0  not have ip address .. ?




More information about the Snort-users mailing list