Am i understanding this right?

Kris Kristensen via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <DBAP192MB0988454704D30E03B269F72BA2769@DBAP192MB0988.EURP192.PROD.OUTLOOK.COM>
Hey all. I have a few questions to Snort, just to make sure i am understanding it right.


  1.  I have used Snort as an IPS system. I know i need two network interfaces to get it to work, but why? Is one network interface for listening on trafic and the other is the interface who is activating the rules i make?

  1.  I have made an test command to test my snort.conf. I am using: sudo snort -T -c /etc/snort/snort.conf -Q -i enp0s3:enp0s8. Does the -T stand for test, and the -c for using it on a console/terminal and -Q for test as inline mode?

Best regards

Kris.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.