[Snort-users] Snort on proxy (outbound alerts)
wkitty42 at ...14940...
Fri Jan 18 12:34:08 EST 2013
On 1/18/2013 06:50, J. H wrote:
> Thank you for answering.
> Only one interface on my proxy machine.
> SQUID/Snort listenin on the same one.
some might consider that to be part of the problem... it sounds like what you
want is for snort to be listening only to your internal machines... you might be
able to use a bpf to block out alerts concerning your proxy...
More information about the Snort-users