my interface wireless isn't understand by snort.lua in mode inline

Dorian ROSSE via Snort-users <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general,gmane.comp.security.ids.snort.sigs
Message-ID <DB7P193MB03467CF6392A6E8A8201D5D7DAF69@DB7P193MB0346.EURP193.PROD.OUTLOOK.COM>
hello,


my interface wireless isn't understand by snort.lua in mode inline :

'''sudo /usr/local/bin/snort -c /usr/local/etc/snort/snort.lua -s 65535 -k all -l /var/log/snort -i enp0s25:wlp3s0 -m 0x1b
--------------------------------------------------
o")~   Snort++ 3.1.21.0
--------------------------------------------------
Loading /usr/local/etc/snort/snort.lua:
Loading snort_defaults.lua:
Finished snort_defaults.lua:
Loading file_magic.lua:
Finished file_magic.lua:
Loading inline.lua:
Finished inline.lua:
Loading talos.lua:
Finished talos.lua:
smtp
ftp_client
http_inspect
http2_inspect
detection
wizard
binder
references
classifications
alert_json
stream_ip
trace
ips
reputation
    Processing blocklist file /usr/local/etc/snort/../lists/default.blocklist
    Reputation entries loaded: 1216, invalid: 0, re-defined: 0 (from file /usr/local/etc/snort/../lists/default.blocklist)
appid
file_policy
file_id
ftp_data
ftp_server
snort
port_scan
dce_http_server
alert_talos
dce_smb
profiler
daq
modbus
output
stream_file
active
alerts
decode
host_cache
host_tracker
hosts
network
packets
process
search_engine
so_proxy
stream
stream_icmp
stream_tcp
stream_udp
stream_user
arp_spoof
back_orifice
dnp3
dns
imap
iec104
netflow
normalizer
pop
rpc_decode
sip
ssh
ssl
telnet
dce_tcp
dce_udp
dce_http_proxy
gtp_inspect
Finished /usr/local/etc/snort/snort.lua:
--------------------------------------------------
rule counts
       total rules loaded: 600
            builtin rules: 600
            option chains: 600
            chain headers: 1
--------------------------------------------------
port rule counts
             tcp     udp    icmp      ip
     any     600       0       0       0
   total     600       0       0       0
--------------------------------------------------
ips policies rule stats
              id  loaded  shared enabled    file
               0     600       0     600    /usr/local/etc/snort/snort.lua
--------------------------------------------------
dump:pcap DAQ configured to inline.
Commencing packet processing
Couldn't construct a DAQ instance: pcap_daq_instantiate: Couldn't open file 'enp0s25:wlp3s0' for reading: No such file or directory (-2)
--------------------------------------------------
Packet Statistics
--------------------------------------------------
Module Statistics
--------------------------------------------------
Summary Statistics
--------------------------------------------------
timing
                  runtime: 00:00:00
                  seconds: 0.001380
o")~   Snort exiting'''

my interface wirelless is good if i run iwconfig :

'''iwconfig
lo        no wireless extensions.

enp0s25   no wireless extensions.

wlp3s0    IEEE 802.11  ESSID:"SFR_80A0"
          Mode:Managed  Frequency:2.437 GHz  Access Point: 6C:61:F4:0C:80:A6
          Bit Rate=144.4 Mb/s   Tx-Power=22 dBm
          Retry short limit:7   RTS thr:off   Fragment thr:off
          Power Management:on
          Link Quality=70/70  Signal level=-38 dBm
          Rx invalid nwid:0  Rx invalid crypt:0  Rx invalid frag:0
          Tx excessive retries:0  Invalid misc:210   Missed beacon:0'''

thank you to help myself fully do work snort3,

Regards.


Dorian ROSSE.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.