Re: Am i understanding this right?
"Al Lewis \(allewi\) via Snort-users" <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
1) Technically… you probably need three interfaces because as an IPS you typically will be inline (can’t block traffic reliably if it all doesn’t go through you). With one interface for management and two for the inline set. Otherwise.. it is an IDS. 2) Run snort -? … that should give you the options and the uses. Albert Lewis ENGINEER.SOFTWARE ENGINEERING Cisco Systems Inc. Email: [email protected]<mailto:[email protected]> From: Snort-users <[email protected]> on behalf of Kris Kristensen via Snort-users <[email protected]> Reply-To: Kris Kristensen <[email protected]> Date: Wednesday, December 15, 2021 at 11:59 AM To: "[email protected]" <[email protected]> Subject: [Snort-users] Am i understanding this right? Hey all. I have a few questions to Snort, just to make sure i am understanding it right. 1. I have used Snort as an IPS system. I know i need two network interfaces to get it to work, but why? Is one network interface for listening on trafic and the other is the interface who is activating the rules i make? 1. I have made an test command to test my snort.conf. I am using: sudo snort -T -c /etc/snort/snort.conf -Q -i enp0s3:enp0s8. Does the -T stand for test, and the -c for using it on a console/terminal and -Q for test as inline mode? Best regards Kris. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette