[sentinix-list] SNORT as a Sniffer
Marlon.Richards-5I9FqcT3+DFWk0Htik3J/[email protected]
| Newsgroups | gmane.linux.sentinix |
|---|---|
| Message-ID | <OF66563E95.C275D4B4-ON05256DFD.0051F304-05256DFD.00529A4D@windalco.com> |
Hi. Just a quick one here about SNORT. I was told that snort was configured as a sniffer. Does it only record traffic as defined in the rule sets or does it record everything on the wire? I realized that someone was abusing my Internet link and wanted to see what was happening there. When i checked the SNORT console i did not see anything too much out of the ordinary. I used another sniffer ( Sniffer Portable from Network associates) and found that i was capturing allot more traffic. The abuser was using a file sharing (P2P) application. I modified the snort.conf file to include the P2P rules and checked the console again but i still did not see evidence of the abuse with SNORT. The SNORT/Sentinix box is connected to a hub that comes off the firewall so it should see all outgoing and incoming traffic. The Sniffer Portable was also placed at the same location when it say all the traffic. Any ideas? This sounds like something i should place on the SNORT mailing list and not the Sentinix! ==================================== Marlon Richards Communications Engineer West Indies Alumina Company Kirkvine Works Jamaica Tel#: 876-961-7434 Fax#: 876-961-7464 Email: marlon.richards-Rzeo2xivIqhWk0Htik3J/[email protected]