[Snort-users] router installation?
Alex Butcher, ISC/ISYS
Alex.Butcher at ...11254...
Tue Oct 5 00:51:56 EDT 2004
--On 05 October 2004 04:18 +1300 Jason Haar <Jason.Haar at ...294...>
> Jason wrote:
>> Once you have logging figured out you have many options on how to
>> actually configure Snort. You can run multiple instances or have Snort
>> monitor the virtual interface "any". If this were not a firewall then
>> interface bonding might be appropriate to enable selective interface
>> monitoring with a single instance of Snort.
> I don't think bonding "disables" using the "raw" Ethernet cards at the
> same time(?).
Interfaces that are slaves to a bondx device certainly cannot be sniffed (I
just checked). I'm not sure whether the same applies to normal IP usage,
but I guess so.
Alex Butcher: Security & Integrity, Personal Computer Systems Group
Information Systems and Computing GPG Key ID: F9B27DC9
GPG Fingerprint: D62A DD83 A0B8 D174 49C4 2849 832D 6C72 F9B2 7DC9
More information about the Snort-users