[Snort-users] snort with two interface

Leonardo Pezente lmpezente at ...11827...
Wed Dec 5 10:52:08 EST 2012


i have the snort in the border of a network, and how this topic shows, it
has two interface. i have put the HOME_NET equal to the ip of the both
interfaces.
the think is: in one of them i can detect attacks, but in the other i cant.
when i start to test, i was using just one (the iterface that is detecting).
but i need particular that the other detect too. so, what could be wrong?
my snort.conf is working fine, and i he is starting on boot sniffing both
interface.
This might be a problem with pcap?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20121205/9e944050/attachment.html>


More information about the Snort-users mailing list