Snort 2.9.7.0 on Ubuntu 20.04.2 LTS problem, please help
lukasz pastewski <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
Hello, everybody, Firstly, I am a beginner concerning SNORT. Please help me to solve my problem. I installed snort 2.9.7.0 on Ubuntu 20.04.2 LTS. After installing I configured everything according to documentation. Snort is set to promisc mode. It was installed on a machine connected to my network. The network consists of server computers (PDC, database servers, terminals etc.), about fifty workstations as well as switches (one of them is managed). The network infrastructure looks like below: | The Internet ---> router (pfsense) ---> SWITCH ---> workstations | So, my problem is like following: If I do nmap, icmp etc. tests in my inner network, snort catches only queries concerning its local IP. For example if I scan computer B (x.x.x.z) using nmap from computer A (x.x.x.x) , snort (x.x.x.a) does not report the scanning (pings too). However pinging or scanning x.x.x.a (snort) from another place in the network is visible in snort logs. I've tried to connect my snort using port mirroring but the result is the same. It is interesting the snort logs show some information, for example connections between workstation and a db server. So please help. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette