[Snort-users] Testing Snort

Keith Konecnik kkonecnik at ...1935...
Wed Apr 29 11:20:35 EDT 2009


You can specify multiple ports or vlans per monitor session on a 2960. Just
make sure in the command you leave a space before and after each dash or
comma.
However monitoring the uplink port is usually the easiest method.

Regards,
Keith

On Wed, Apr 29, 2009 at 12:56 AM, -AnaS- _____ <pxxanasxxq at ...125...>wrote:

>  Hello evryone,
> I am very happy to post you this email , this is my first time,
>
> I have instaled snort , apache server , mysql database , and the interface
> "BASE"
>
> it's running good , now i have to test intrusion and attacks
> can you help me , guide me ??
>
> I already tested scan.  I should test "Arp spoofing" and "Arp flooding" and
> others...
>
> second point , i have to configure a port mirroring in the switch to
> reflect traffic to the port which my snort is installed,
> I did it but just from one port source to destination port (cisco switch :
> catalyst 2960)
>
> when i tried more than source port , it dosen't work
>
> Thank you very much
>
>
>
> A.i.A
>
> ------------------------------
> Découvrez tout ce que Windows Live a à vous apporter !<http://www.microsoft.com/windows/windowslive/>
>
>
> ------------------------------------------------------------------------------
> Register Now & Save for Velocity, the Web Performance & Operations
> Conference from O'Reilly Media. Velocity features a full day of
> expert-led, hands-on workshops and two days of sessions from industry
> leaders in dedicated Performance & Operations tracks. Use code vel09scf
> and Save an extra 15% before 5/3. http://p.sf.net/sfu/velocityconf
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users<https://lists.sourceforge.net/lists/listinfo/snort-users%0ASnort-users>list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20090429/47466154/attachment.html>


More information about the Snort-users mailing list