[Snort-users] router installation?

Alex Butcher, ISC/ISYS Alex.Butcher at ...11254...
Tue Oct 5 00:51:56 EDT 2004


--On 05 October 2004 04:18 +1300 Jason Haar <Jason.Haar at ...294...> 
wrote:

> Jason wrote:
>
>> Once you have logging figured out you have many options on how to
>> actually configure Snort. You can run multiple instances or have Snort
>> monitor the virtual interface "any". If this were not a firewall then
>> interface bonding might be appropriate to enable selective interface
>> monitoring with a single instance of Snort.
>
>
> I don't think bonding "disables" using the "raw" Ethernet cards at the
> same time(?).

Interfaces that are slaves to a bondx device certainly cannot be sniffed (I 
just checked). I'm not sure whether the same applies to normal IP usage, 
but I guess so.

> Jason

Best Regards,
Alex.
-- 
Alex Butcher: Security & Integrity, Personal Computer Systems Group
Information Systems and Computing             GPG Key ID: F9B27DC9
GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9






More information about the Snort-users mailing list