Inline mode
Ollie Campbell via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CAJ1Kq9HqQhcQeEZ2DSkGWWE=kmbdaOZcnvvDva4z5F3+9_-cHw@mail.gmail.com> |
Hi Everyone, I'm trying to get Snort3 to run in inline mode, so that I can place my Snort box in between the LAN and Firewall. Firstly, has anyone found any good documentation on this? Secondly, does each interface have to sit on different subnets or will it still pass the traffic through if they are both on the same subnet? Lastly, I'm running into a problem: *Couldn't start DAQ instance: No such device exists (-1)Analyzer: Failed to start DAQ instance* My service is setup as follows: */usr/local/bin/snort -c /usr/local/etc/snort/snort.lua -s 65535 -k none -l /var/log/snort -D -u snort -g snort -i enp2s0:enx00e04cb63e73 -Q -m 0x1b --create-pidfile --plugin-path=/usr/local/etc/so_rules/* I haven't bridged the connections in the underlying OS, but presume Snort can run fine without this using the above configuration. Thanks -- Barton Blakeley Technologies Ltd. Registered Office : Rothamsted Research Institute, West Common, Harpenden, AL5 2JQ. Registered in England, no. 10454937. CONFIDENTIALITY - What we have written in this email is intended for you and only you. If it's not appropriate or relevant for your eyes, let us know rather than passing it around the world and getting us into trouble. Please don't share it with everyone you've ever met or copy it and keep it to use against us at a later date. Let's all be open and transparent and stay friends. Thanks. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette