[Snort-users] snort with two interface

Lay, James james.lay at ...15009...
Wed Dec 5 10:58:59 EST 2012


 

 

From: Leonardo Pezente [mailto:lmpezente at ...11827...] 
Sent: Wednesday, December 05, 2012 8:52 AM
To: snort-users at lists.sourceforge.net
Subject: [Snort-users] snort with two interface

 

i have the snort in the border of a network, and how this topic shows,
it has two interface. i have put the HOME_NET equal to the ip of the
both interfaces.

the think is: in one of them i can detect attacks, but in the other i
cant. 

when i start to test, i was using just one (the iterface that is
detecting).

but i need particular that the other detect too. so, what could be
wrong?

my snort.conf is working fine, and i he is starting on boot sniffing
both interface.

This might be a problem with pcap?

 

I believe Snort can only listen on one interface at a time, so you may
want to run two separate instances of snort.

 

James

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20121205/44471c88/attachment.html>


More information about the Snort-users mailing list