Snort 2.9.7.0 on Ubuntu 20.04.2 LTS problem, please help

lukasz pastewski <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
Hello, everybody,
Firstly, I am a beginner concerning SNORT. Please help me to solve my problem. I installed snort 2.9.7.0 on Ubuntu 20.04.2 LTS. After installing I configured everything according to documentation. Snort is set to promisc mode. It was installed on a machine connected to my network. The network consists of server computers (PDC, database servers, terminals etc.), about fifty workstations as well as switches (one of them is managed). The network infrastructure looks like below:
|
The Internet ---> router (pfsense) ---> SWITCH ---> workstations
|
So, my problem is like following:
If I do nmap, icmp etc. tests in my inner network, snort catches only queries concerning its local IP. For example if I scan computer B (x.x.x.z) using nmap from computer A (x.x.x.x) , snort (x.x.x.a) does not report the scanning (pings too). However pinging or scanning x.x.x.a (snort) from another place in the network is visible in snort logs. I've tried to connect my snort using port mirroring but the result is the same.
It is interesting the snort logs show some information, for example connections between workstation and a db server.
So please help.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.