AW: [Snort-users] Ethernet Tap

Matt Kettler mkettler at ...4108...
Fri Apr 16 08:06:45 EDT 2004


At 08:46 AM 4/16/2004, Altrock, Jens wrote:
>First thanks for the answers, and sorry for another dumb question. :-/
>I thought about that this thing isn't working that way, but there is
>anyway a problem concerning that two port solution. I'd need a software that
>reassembles the network traffic in a way right? For I need both lines
>(TX and RX) to analyze "special" or more complex attacks. So is there any
>affordable software that does that?

Yes, most modern *nix OSes do it.. You can make a bonded interface that 
combines the two.

See this post from the archives:

http://archives.neohapsis.com/archives/snort/2002-03/0846.html

>  Or is there any solution for that
>problem?





More information about the Snort-users mailing list