[Snort-users] Ethernet Tap

Frank Knobbe frank at ...9761...
Fri Aug 13 11:49:01 EDT 2004


On Fri, 2004-08-13 at 13:31, STEVE MAKOUSKY wrote:
> If not is it easy enough to start snort on two nics and log to the
> same database and 
> handle packet reconstruction that way????

Uhm... no. Who would be doing the reconstruction? Snort isn't, the
database isn't.

Sorry, if you want to sniff a single data stream on two NICS
(split-tap), you would need to configure these NICs in bridge-mode, or
somehow else have the OS treat both NICs as a single NIC.

Regards,
Frank

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 187 bytes
Desc: This is a digitally signed message part
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20040813/9aed1c27/attachment.sig>


More information about the Snort-users mailing list