[Snort-users] Redirect foo.

James Lay jlay at ...13475...
Mon Aug 29 07:53:02 EDT 2011



On 8/28/11 4:05 PM, "Paul Halliday" <paul.halliday at ...11827...> wrote:

>I have a vm on a linux host. The host has one public address (eth0)
>and numerous vm's listening on a single virtual interface (vm0).
>
>I want to redirect all traffic to my vm (10.0.0.1) from eth0 w/o
>leaking into other vms. I had originally planned on using daemonlogger
>but I notice it is if1 -> if2. Maybe tcpreplay, iptables?
>what I am looking for is eth0 -> 10.0.0.1
>
>What are my options?
>
>Thanks!
>-- 
>Paul Halliday
>http://www.squertproject.org/


Paul,

Take a look at ebtables perhaps...should be able to redirect using MAC
addresses.

James






More information about the Snort-users mailing list