Re: Compiling and Running Snort 2.9.8.0 on MAC OSX 10.11.3 (El Capitan)

Bill Parker <[email protected]>
Newsgroups gmane.comp.security.ids.snort.devel
Message-ID <CAFrbyQxCtJwB0=t_cwB6hUSYHHSG=jLpetdpYq2R7g2_baajgw@mail.gmail.com>
Here is a URL to get the device listings in MacOS X at the command line:

http://osxdaily.com/2014/09/03/list-all-network-hardware-from-the-command-line-in-os-x/

It would appear that interface names start with 'en' in MacOS (from what is
listed in the URL)...

Bill

On Mon, Feb 15, 2016 at 11:39 AM, Joel Esler (jesler) <[email protected]>
wrote:

> I don’t think that the interface would be called “eth0” on a mac.  You may
> want to make sure you have the right device specified.
>
> --
> *Joel Esler*
> Manager, Talos Group
>
>
>
>
> On Feb 12, 2016, at 5:04 PM, Madhu Rao <[email protected]> wrote:
>
> Hi Folks
>
> Has anyone had Luck downloading and compiling snort 2.9.8.0 and get it
> working on Latest MAC OS X El Capitan ?
> I have a macbook pro running El Capitan. (OSX 10.11.3)
>
> I See the following Errors when I run Snort.
>
> $ sudo snort -c /etc/snort/snort.conf --daq pcap --daq-mode passive -i
> eth0 -k none
>
> pcap DAQ configured to passive.
>
> Acquiring network traffic from "eth0".
>
> Reload thread starting...
>
> Reload thread started, thread 0x700000081000 (41553)
>
> ERROR: Can't start DAQ (-1) - BIOCSETIF failed: Device not configured!
>
> Fatal Error, Quitting..
>
>
> BTW - when I configured DAQ, this was the outcome.
>
> $cd daq-2.0.6
>
> ./configure --disable-afpacket-module
>
> ...
>
> Build AFPacket DAQ module.. : no
> Build Dump DAQ module...... : yes
> Build IPFW DAQ module...... : yes
> Build IPQ DAQ module....... : no
> Build NFQ DAQ module....... : no
> Build PCAP DAQ module...... : yes
> Build netmap DAQ module.... : no
>
>
> Any pointers appreciated.
>
> -- madhu
>
>
>
> ------------------------------------------------------------------------------
> Site24x7 APM Insight: Get Deep Visibility into Application Performance
> APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month
> Monitor end-to-end web transactions and take corrective actions now
> Troubleshoot faster and improve end-user experience. Signup Now!
>
> http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140_______________________________________________
> Snort-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/snort-devel
> Archive:
> http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel
>
> Please visit http://blog.snort.org for the latest news about Snort!
>
>
>
>
> ------------------------------------------------------------------------------
> Site24x7 APM Insight: Get Deep Visibility into Application Performance
> APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month
> Monitor end-to-end web transactions and take corrective actions now
> Troubleshoot faster and improve end-user experience. Signup Now!
> http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140
> _______________________________________________
> Snort-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/snort-devel
> Archive:
> http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel
>
> Please visit http://blog.snort.org for the latest news about Snort!
>

------------------------------------------------------------------------------
Site24x7 APM Insight: Get Deep Visibility into Application Performance
APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month
Monitor end-to-end web transactions and take corrective actions now
Troubleshoot faster and improve end-user experience. Signup Now!
http://pubads.g.doubleclick.net/gampad/clk?id=272487151&iu=/4140

_______________________________________________
Snort-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/snort-devel
Archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-devel

Please visit http://blog.snort.org for the latest news about Snort!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.