[Snort-users] Stealth Interface

Harper, Patrick patrick.harper at ...11593...
Wed Jul 14 16:44:01 EDT 2004


Most likely, depending on your setup, change the sniffing interface in
the init script /etc/init.d/snort.  As for making the interface not have
an IP got to /etc/sysconfig/network-scripts and modify the file for eth0
to have 0.0.0.0 as an IP





-----Original Message-----
From: b7time b7time [mailto:b7time at ...125...] 
Sent: Friday, July 09, 2004 10:09 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] Stealth Interface

I have Snort running on Linux 9 with two interfaces. Eth0 has an IP
address assigned and is capturing traffic. However I would like to use
instead eth1 without an IP address that is attached to a hub on the
external network. How do I 'unbind' Snort from using eth0 (which I would
use for management) and instead use eth1 (no IP address) in stealth
mode?

Thanks in advance.

Vito

_________________________________________________________________
Is your PC infected? Get a FREE online computer virus scan from
McAfee(r) Security.
http://clinic.mcafee.com/clinic/ibuy/campaign.asp?cid=3963



-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=4721&alloc_id=10040&op=click
_______________________________________________
Snort-users mailing list
Snort-users at lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users





Disclaimer:
This electronic message, including any attachments, is confidential and intended solely for use of the intended recipient(s). This message may contain information that is privileged or otherwise protected from disclosure by applicable law. Any unauthorized disclosure, dissemination, use or reproduction is strictly prohibited. If you have received this message in error, please delete it and notify the sender immediately. 







More information about the Snort-users mailing list