Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Snort-users] Re: Inline IP_Forwarding and other simple questions? |
|---|---|
| Date: | Tue, 28 Dec 2004 17:47:46 -0600 |
Sounds good to me, although it sounds like an awful lot of traffic to watch for one box. Watch out for bus/memory/processor limitations. I can just see that poor 386 trying to move those packets through ip_queue now ;-) Regards, Will On Tue, 28 Dec 2004 18:40:00 -0500, Michael D. Peters <mdpeters@lazarusalliance.com> wrote:
What I have is 4 unnumbered sensor interfaces, 2 unnumbered interfaces for the bridge, and 1 numbered interface for the management port. I have not turned on ip_forwarding at any time. How does this sound? Will Metcalf writes:It's that true? I almost can believe it. I enable ip_forwarding and then I pass some traffic with QUEUE to snort-inline so I can take another look at it. Am I doing it all wrong? Can you explain me why?There is no need to enable ip_forwarding if you are in bridge mode. The brnf code moves data across the bridge for you. There is no need for an ip interface or anything. If you are running ip_forwarding in bridge mode turn it off. If you have a third management int or an ip assigned to the bridge interface this may lead to an insecure configuration. Regards, Will On 28 Dec 2004 23:43:19 +0100, Jose Maria Lopez <jkerouac@bgsec.com> wrote:El jue, 23 de 12 de 2004 a las 21:21, Matt Kettler escribió:At 02:04 PM 12/23/2004, mdpeters wrote:Do I need to enable ip_forwarding on for the transparent bridge to work?As I understand it, you explicitly MUST NOT enable ip_forwarding, otherwise your snort-inline is a "pass all".It's that true? I almost can believe it. I enable ip_forwarding and then I pass some traffic with QUEUE to snort-inline so I can take another look at it. Am I doing it all wrong? Can you explain me why? Thanks and Happy Christmas to everybody. -- Jose Maria Lopez Hernandez Director Tecnico de bgSEC jkerouac@bgsec.com bgSEC Seguridad y Consultoria de Sistemas Informaticos http://www.bgsec.com ESPAÑA The only people for me are the mad ones -- the ones who are mad to live, mad to talk, mad to be saved, desirous of everything at the same time, the ones who never yawn or say a commonplace thing, but burn, burn, burn like fabulous yellow Roman candles. -- Jack Kerouac, "On the Road" ------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://productguide.itmanagersjournal.com/ _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?listsnort-users------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://productguide.itmanagersjournal.com/ _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?listsnort-users
------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://productguide.itmanagersjournal.com/ _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-users] Inline IP_Forwarding and other simple questions?, Will Metcalf |
|---|---|
| Next by Date: | [Snort-users] How can you verify if snort is using libpcap mmap mode?, Basselgia, Barry A Mr (NAF Atsugi) |
| Previous by Thread: | Re: [Snort-users] Inline IP_Forwarding and other simple questions?, Will Metcalf |
| Next by Thread: | [Snort-users] Snort Rules, mosquitooth |
| Indexes: | [Date] [Thread] [Top] [All Lists] |