[Snort-users] Snort on proxy (outbound alerts)

waldo kitty wkitty42 at ...14940...
Fri Jan 18 12:34:08 EST 2013


On 1/18/2013 06:50, J. H wrote:
> Hi,
>
> Thank you for answering.
>
> Only one interface on my proxy machine.
>
> SQUID/Snort listenin on the same one.

some might consider that to be part of the problem... it sounds like what you 
want is for snort to be listening only to your internal machines... you might be 
able to use a bpf to block out alerts concerning your proxy...






More information about the Snort-users mailing list