Re: Listening to all devices

Ron Jenkins via Snort-users <[email protected]> Fri, 1 Mar 2024 15:59:54 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <SN6PR13MB2432D0490986F12687357702E15E2@SN6PR13MB2432.namprd13.prod.outlook.com>
Good morning

She is correct, two interfaces (management and monitoring).  Been deploying Snort for over 20yrs in all deployment types including as a VM.  My  OS of choice is Ubuntu Server.


Thx

From: Snort-users <[email protected]> On Behalf Of Andrian Andrian
Sent: Friday, March 1, 2024 6:40 AM
To: Paul Giovanni <[email protected]>; [email protected]
Subject: Re: [Snort-users] Listening to all devices


CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders.
By that, I assume you’re referring to port mirroring. It is not something I’ve tried myself, but articles I’ve found no the internet suggests it’s doable.

This does mean that you’d need (preferably) two virtual interfaces on your VMs; one for working with the VM, and the other to receive mirrored traffic.

I haven’t reviewed the following articles in details as it’s 11.37 PM Friday here in Melbourne (Australia), but I believe it’ll give you a clear idea on how this could be implemented in your environment.

Setting up Snort - Part 1 - Overview · Don Mizutani<http://donmizutani.com/pages/snort/setup/1-overview/>

From: Paul Giovanni <[email protected]<mailto:[email protected]>>
Sent: Friday, March 1, 2024 11:03 PM
To: Andrian Andrian <[email protected]<mailto:[email protected]>>; [email protected]<mailto:[email protected]>
Subject: Re: Listening to all devices

You don't often get email from [email protected]<mailto:[email protected]>. Learn why this is important<https://aka.ms/LearnAboutSenderIdentification>
Is there any chance I can just mirror the traffic to my VM? We have a decent firewall

Get Outlook for Android<https://aka.ms/AAb9ysg>
Paul Giovanni​​​​
IT Project Manager
Edison, NJ<https://goo.gl/alXFy5> P: <tel:7329855000> (732) 985-5000<tel:7329855000>
Gloucester City, NJ<https://goo.gl/PgMNnW> P: (856) 212-0050<tel:8562120050>
[Facebook]<https://www.facebook.com/RaritanGroup/>
[Instagram]<https://www.instagram.com/raritangroup/>
[LinkedIn]<https://www.linkedin.com/company/raritan-group>
[cid:[email protected]]<http://www.raritangroup.com/>


________________________________
From: Andrian Andrian <[email protected]<mailto:[email protected]>>
Sent: Friday, March 1, 2024 6:50:34 AM
To: Paul Giovanni <[email protected]<mailto:[email protected]>>; [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]>>
Subject: RE: Listening to all devices

You don't often get email from [email protected]<mailto:[email protected]>. Learn why this is important<https://aka.ms/LearnAboutSenderIdentification>

Hi Paul,



I believe that is how Snort works, unless it is installed on your router/gateway/firewall and configured to monitor traffic on your LAN port, in which case it would be able to monitor traffic between your internal endpoints and the gateway.



From: Snort-users <[email protected]<mailto:[email protected]>> On Behalf Of Paul Giovanni
Sent: Thursday, February 29, 2024 12:26 AM
To: [email protected]<mailto:[email protected]>
Subject: [Snort-users] Listening to all devices



You don't often get email from [email protected]<mailto:[email protected]>. Learn why this is important<https://urldefense.proofpoint.com/v2/url?u=https-3A__aka.ms_LearnAboutSenderIdentification&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=4OZSCmiNx6Z07N5dsJ74H30geLOwnkB7ayE-SDu4vuqk5Ign75FgFg0d93Uge6Ev&s=UgApfkA9Wa9_KSZrPYnqLcMvte-PUJjwAoA55ED5UW4&e=>

Hello Snort community,



I am trying to get snort to detect all network packets on all network devices, but right now it seems to only be listening on the device I have it installed on. Is there something I’m missing? My config has



-- HOME_NET and EXTERNAL_NET must be set now

23 -- setup the network addresses you are protecting

24 HOME_NET = '10.0.0.0/24'



All I’m seeing are broadcast messages.



Thanks,



Paul Giovanni​​​​

IT Project Manager

Edison, NJ<https://urldefense.proofpoint.com/v2/url?u=https-3A__goo.gl_alXFy5&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=4OZSCmiNx6Z07N5dsJ74H30geLOwnkB7ayE-SDu4vuqk5Ign75FgFg0d93Uge6Ev&s=0MsV-Zu8ur2kHqcumb40zUMzFbjD-0eFqbYPPuA0Fv8&e=> P: <tel:7329855000> (732) 985-5000<tel:7329855000>

Gloucester City, NJ<https://urldefense.proofpoint.com/v2/url?u=https-3A__goo.gl_PgMNnW&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=4OZSCmiNx6Z07N5dsJ74H30geLOwnkB7ayE-SDu4vuqk5Ign75FgFg0d93Uge6Ev&s=yOjVvSEOuX7pip66dYnNj4mU8932t6GWXeKPbBTzCDs&e=> P: (856) 212-0050<tel:8562120050>

[cid:[email protected]]<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.facebook.com_RaritanGroup_&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=4OZSCmiNx6Z07N5dsJ74H30geLOwnkB7ayE-SDu4vuqk5Ign75FgFg0d93Uge6Ev&s=H57dB1O2o2bSuORmgMcnHErO_e1RiMgTv6XnCv9Wiic&e=>

[cid:[email protected]]<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.instagram.com_raritangroup_&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=4OZSCmiNx6Z07N5dsJ74H30geLOwnkB7ayE-SDu4vuqk5Ign75FgFg0d93Uge6Ev&s=nPo25COnj7-OSySHbw2OCEft90CVMoFnmhniAk2AmqE&e=>

[cid:[email protected]]<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.linkedin.com_company_raritan-2Dgroup&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=4OZSCmiNx6Z07N5dsJ74H30geLOwnkB7ayE-SDu4vuqk5Ign75FgFg0d93Uge6Ev&s=HrhD-7r61aUvRTEm6M-_T5zwiaQpf44BIiug2jS1LsU&e=>

[cid:[email protected]]<https://urldefense.proofpoint.com/v2/url?u=http-3A__www.raritangroup.com_&d=DwMGaQ&c=euGZstcaTDllvimEN8b7jXrwqOf-v5A_CdpgnVfiiMM&r=h7KmwhwQTf-8idLOkUGqw_U9le4wAdZNjMPKN0d78EY&m=4OZSCmiNx6Z07N5dsJ74H30geLOwnkB7ayE-SDu4vuqk5Ign75FgFg0d93Uge6Ev&s=rfIOv7BKoUwTEMXHA92V3Kl7rxdEz5GmFSbircg-B_Q&e=>









________________________________

This email has been scanned for spam and viruses. Click here<https://godaddy.cloud-protect.net/app/report_spam.php?mod_id=11&mod_option=logitem&report=1&type=easyspam&k=k1&payload=53616c7465645f5faef68e30375a5c06ddb3fe7f675a868f824c8cea6b0afa6ffbefd70edf8372f104debd39ce47a65aeee95c2e7032897c95a9f0933862028d8689ce61e3c26b18ac5a8c54d88277aa9feee1281be5eb4700be1dc17c1d03550ba81a4d98719e6d183afa3173206fe7cd5c68fe9950be6cb414738444b8a82e86e34c9445651510b677d48845a95da3a2245f7147367caa30b68520941c99a5> to report this email as spam.
PRIVILEGED & CONFIDENTIAL COMMUNICATION:
The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message.

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
image001.png (image/png, 641 B) - not displayed
image002.png (image/png, 905 B) - not displayed
image003.png (image/png, 642 B) - not displayed
image004.jpg (image/jpeg, 45.8 KB) - not displayed