[Snort-users] Multiple sensors/interfaces, same daemon
Todd.Murray at ...12036...
Fri Jul 2 12:09:01 EDT 2004
The easiest way to do it is to just run separate processes.
/usr/local/bin/snort -c /etc/snort/snort.eth0.conf -ieth0 -u snort -g snort
/usr/local/bin/snort -c /etc/snort/snort.eth1.conf -ieth1 -u snort -g snort
This way I can keep each sensor running completely separate of the other.
If you want them to have them use 1 config just make sure to set HOME_NET to
include the networks for both interfaces.
var HOME_NET [10.1.1.0/24,126.96.36.199/24]
Just remember that unless you specify the interface it will assume "any".
I've found its much better to isolate snort as a non-privledged user/group
and manage each interface as a separate sensor under separate processes.
From: snort-users-admin at lists.sourceforge.net
[mailto:snort-users-admin at lists.sourceforge.net] On Behalf Of Sergio
Sent: Thursday, July 01, 2004 11:00 AM
To: Snort-users at lists.sourceforge.net
Subject: [Snort-users] Multiple sensors/interfaces, same daemon
Hey all, how do i configure a single snort daemon to act as a sensor on two
When I try '-i any' i pick up alot of traffic from 127.0.0.1 - which I'm
guessing is the loopback; however, I get none from eth1 and just fine from
Also, with 2 interfaces, how should the $HOME_NET and $EXTERNAL_NET be set?
This SF.Net email sponsored by Black Hat Briefings & Training. Attend Black
Hat Briefings & Training, Las Vegas July 24-29 -
digital self defense, top technical experts, no vendor pitches,
unmatched networking opportunities. Visit www.blackhat.com
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
Snort-users list archive:
More information about the Snort-users