[Snort-users] IPless interface on Debian...

M. Morgan mikemorgan at ...468...
Wed Feb 11 10:23:23 EST 2004


Tobias, 
I cant speak for Debian specifically but you should be able to use any regular method of NIC managment, (GUI or Text based) to assign an IP# of 0.0.0.0/ netmask 255.255.255.255 to eth0 and whatever you like to eth1.

 You should set IP Tables (or whatever FW you use) to drop all incoming connection attempts on eth0 as well.

Use tcpdump to verify that eth0 is indeed sniffing traffic on the hostile lan.

michael 




-----Original Message-----
From: Tobias Rice <rice at ...7669...>
Sent: Feb 11, 2004 11:57 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] IPless interface on Debian...

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello Snort-Users,

I hope this isn't redundant, but the archives seem to be down right now.

I have two NIC's, eth1 is for my management network, and eth0 is for
sniffin'. I want eth0 *not* to have a IP address. This worked fine in
RedHat, but since they eol'ed it I'm migrating to Debian, and I'm a
little green. How is this done in Debian?
Many Thanks,
Tobias
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFAKl8FRJX8S0T0CkURAj/CAKC6y1dVURILJNkbEPQ656BeAZu7tACfWsuX
iKyFAMGBtB+axBetoypmSLo=
=VCcb
-----END PGP SIGNATURE-----



-------------------------------------------------------
SF.Net is sponsored by: Speed Start Your Linux Apps Now.
Build and deploy apps & Web services for Linux with
a free DVD software kit from IBM. Click Now!
http://ads.osdn.com/?ad_id=1356&alloc_id=3438&op=click
_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users





More information about the Snort-users mailing list