[Snort-users] a lot of Loopback traffic being logged.
hbloomb at ...11694...
Thu Apr 22 11:28:00 EDT 2004
On Thu, 22 Apr 2004, Chuck Holley wrote:
> OK, I think im on to something. I do not use the -i option, only -c to look
> at the conf. in the conf I have for "HOME_NET 192.168.10.0/24" and a little
> further down I have "HOME_NET any"
We are forcing Snort to listen to one real port only with the -i
option, and we're also seeing a *lot* of packets with a source of
127.0.0.1:80. This was confirmed by one of our network guys who plugged another
packet sniffer into the Snort port. This seems to be real traffic, and
we're baffled by the source.
More information about the Snort-users