[Snort-users] Snort on proxy (outbound alerts)

Balasubramaniam Natarajan bala150985 at ...11827...
Fri Jan 18 06:24:02 EST 2013


On Fri, Jan 18, 2013 at 4:29 AM, Thibaud Raso <joga3.web at ...11827...> wrote:

> Hi everybody,
>
> I'm having a problem with my running instance of Snort which is setup on
> my proxy server(squid), and uses the ET ruleset.
> I've been looking for a solution for a while, but I still have no answer.
> My problem is, that for some rules, it alerts me on outbound traffic
> instead of inbound traffic, let me explain:
>
>
Could you let us know the number of interface on your proxy server ?

Which interface are you making snort listen on ?

Which interface is your proxy listening on ?

-- 
Regards,
Balasubramaniam Natarajan
www.blog.etutorshop.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20130118/fcbad573/attachment.html>


More information about the Snort-users mailing list