This is a discussion on [Snort-users] snort on a worksation (fc1) <-- router <-- cable-modem <-- internet within the Snort forums, part of the System Security and Security Related category; Hello dear mailing list users ! Question about snort and snort.conf more precisely var HOME_NET: I'm using 192.168....
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
Hello dear mailing list users !
Question about snort and snort.conf more precisely var HOME_NET: I'm using 192.168.1.1 for the router, ..2 to .10 and .192 are internal WStation. I would like to monitor for internet activity and not the internal activity, but I'm having trouble understanding how to do that with a router. (and for sure, activity on the workstation with snort, which is, let say, 192.168.1.3) So it will look like this : var HOME_NET [192.168.1.0/24] but what happen if 192.168.1.1 is the router ? and what about the workstation with snort (192.168.1.3) ? My snort logs are awfully big :( Thanks a million ! ------------------------------------------------------- This SF.Net email is sponsored by Sleepycat Software Learn developer strategies Cisco, Motorola, Ericsson & Lucent use to deliver higher performing products faster, at low TCO. http://www.sleepycat.com/telcomwpreg...rom=osdnemail3 _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |