[Snort-users] a lot of Loopback traffic being logged.

Harry Bloomberg hbloomb at ...11694...
Thu Apr 22 11:28:00 EDT 2004

On Thu, 22 Apr 2004, Chuck Holley wrote:

> OK, I think im on to something.  I do not use the -i option, only -c to look
> at the conf.  in the conf I have for "HOME_NET" and a little
> further down I have "HOME_NET any"
   We are forcing Snort to listen to one real port only with the -i
option, and we're also seeing a *lot* of packets with a source of  This was confirmed by one of our network guys who plugged another
packet sniffer into the Snort port.  This seems to be real traffic, and
we're baffled by the source.

Harry Bloomberg

More information about the Snort-users mailing list