Re: [SLUG] Snort!

From: Russell Hires (rhires@earthlink.net)
Date: Sun Jul 28 2002 - 14:05:30 EDT


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> You can also do something like this:
>
> var HOME_NET [192.168.1.0/24,$ppp0_ADDRESS]
>
> But then you need to restart snort everytime to bring up ppp0.

So I can have my local addresses, which are behind my firewall (the 192....
range, and on eth1) and my external, dynamically assigned address (4......,
on ppp0) all as part of the HOME_NET variable? Okay. That's cool! But I guess
that snort is sniffing for packets that come across the ppp0 interface.
Right?
>
> HTH!

It does help. I'm getting there veeerrrryyy slowly.... :-)

Russell
- --
Linux -- the OS for the Renaissance Man
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE9RDJtAqKGrvVshJQRAv2gAKDgYD1FaHZow0P3Q5skoS/QV6UwMgCgwO58
MYHCVdlDzsej71gX1zlNv7s=
=G4Ok
-----END PGP SIGNATURE-----



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 14:46:41 EDT