[Snort-users] .i eth1

Matt Kettler mkettler at ...4108...
Fri Nov 21 08:38:17 EST 2003


At 04:29 AM 11/21/2003, Timm Schneider wrote:
>snort -c /etc/snort/snort.conf -A full -D
>and
>snort -c /etc/snort/snort.conf  -i eth1-A full -D
>
>In my snort.conf the eth0 and eth1 are configurated,
>so the eth0 and eth1 Interface must be monitored.

Um, how did you "configurate" eth0 and eth1 in your snort.conf.. AFAIK you 
only specify addresses for HOME_NET, etc.. this doesn't have anything to do 
with what interfaces snort will listen on.

>But when i say i- eth1 is than the eth0 also monitored like
>the conf File said?

No, because that's not what the conf file stated. It will listen on eth1, 
but will be looking for attacks going to the address ranges you specfied. 





More information about the Snort-users mailing list