[Snort-users] Monitoring multiple devices with SNORT

Harper, Patrick patrick.harper at ...11593...
Mon Apr 12 06:21:05 EDT 2004

What are you using for a hub? Most of the products that are labeled
"hubs" today and really switches.  If it is dual speed it is a switch.
I went out and found an older 4 port 100 mbs hub on e-bay that did the
job because I could not find one locally in the computer stores.  There
was a thread about this also if you want to search the archives, I think
it was about 6 months ago.

Patrick S. Harper | CISSP RHCT MCSE
Information Security Engineer
patrick.harper at ...11593... 

-----Original Message-----
From: David Nardoni [mailto:dnardoni at ...11606...] 
Sent: Thursday, April 08, 2004 11:06 AM
To: snort-users at ...314...
Subject: [Snort-users] Monitoring multiple devices with SNORT

I want to monitor some traffic outside my firewall.

Here is how I have things set up

Internet ------  hub ---- firewall ------ LAN

I am getting hits directly on the snort box and I am showing traffic
coming out of the LAN but I do not appear to be showing the traffic
coming from the internet to the firewall.

Any suggestions on where to look for the problems.

David Nardoni CISSP
First Response Consulting Services, Inc.  
dnardoni at ...11606... 

This SF.Net email is sponsored by: IBM Linux Tutorials Free Linux
tutorial presented by Daniel Robbins, President and CEO of GenToo
technologies. Learn everything from fundamentals to system
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:

This electronic message, including any attachments, is confidential and intended solely for use of the intended recipient(s). This message may contain information that is privileged or otherwise protected from disclosure by applicable law. Any unauthorized disclosure, dissemination, use or reproduction is strictly prohibited. If you have received this message in error, please delete it and notify the sender immediately. 

More information about the Snort-users mailing list