Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: [Snort-users] Multi interface problem |
|---|---|
| Date: | Mon, 28 Feb 2005 16:34:19 -0500 |
Ah, great info. I was just thinking about this. I haven't had time to try it yet and am not physically near my console so I have one question for both the "any" and "-i bond0" solutions: - Does the image size of snort increase when you increase the number of interfaces being snorted? I have a low-memory system monitoring a low-bandwidth home environment and I would not like to see the amount of memory consumed by snort double/triple/quadruple based on snorting 2/3/4 interfaces simultaneously. Thanks, Steve
El sáb, 26-02-2005 a las 14:49 +0800, abanger wu escribió:snort -i eth0 eth1 eth2 -c /etc/snort/snort.confYou can't use this syntax, you can't use more than one interface for the switch -i. If you are running Linux you can use the interface "any" to ask snort to listen on all interfaces.Or, alternatively, bond them together, then use '-i bond0'. Jose's suggestion is best if you want to use different configurations for each instance of snort (and even better if you have multiple CPUs in your sensor host), using bonding is better if you're happy with a single configuration and you want better tracking of the state of connections. Swings n' roundabouts.
------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://ads.osdn.com/?ad_ide95&alloc_id396&opÌk _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Snort-users] writing rule with uricontent keyword, Edin Dizdarevic |
|---|---|
| Next by Date: | RE: [Snort-users] snort newbie help, Guillermo Padilla |
| Previous by Thread: | Re: [Snort-users] Multi interface problem, Senthil Prabu.S |
| Next by Thread: | [Snort-users] snort -2.3.0 with sfPortscan dumps core, Senthil Prabu.S |
| Indexes: | [Date] [Thread] [Top] [All Lists] |