Skip to main content

Thread: SNORT on only one interface?


i have installed snort repository, , installed acidbase , have working , functional. ids sitting behind asa firewall, listening nic in promisc mode, connected spanned port on asa. other main nic connected internal network, remote administration , other monitoring. snort generating lots of "alerts" on internal network don't care see @ point in time.

go ensure snort active on listening interface? poked around in /etc/init.d/snort , snort.conf, not sure look. have change home_net match ip range of interface listening on? mean traffic want see outside traffic website behind firewall. hoping there way start snort flag enables listening on interface choose. appreciated!

well think found need create new "sensor" maybe? looking in acidbase pages, see there's 1 configured in /acidbase/base_stat_sensor.php, , it's bound internal interface. i'll dig through snort pages , see if can find anything, in meantime if can chime in i'll watching!

#edit#

what did, using base, start 2 instances of snort , vary "-i " parameter on command line, , used same snort.conf each. neither sensor id nor the interface mentioned anywhere in snort.conf. new sensor ids automatically generated, , base can distinguish between them fine. 1 database needed, , 1 base instance needed. alerts displayed intermixed, fine me. details show sensor, source , dest ip, etc, involved. of course, if want separate them using separate databases can.
i found while trawling intarwebz. looks since need 1 interface listening, need find out edit startup options created when installed repository. other tutorials have me setting source, i'd stay packages since makes upgrading in future less hassle.


Forum The Ubuntu Forum Community Ubuntu Official Flavours Support General Help [ubuntu] SNORT on only one interface?


Ubuntu

Comments

Popular posts from this blog

Joomla site hacked, cant see front and - Joomla! Forum - community, help and support

Christian Home School Programs - Joomla! Forum - community, help and support

Trouble with PF_OutFlag_I_USE_AUDIO and PF_CHECKOUT_LAYER_AUDIO