RE: [sentinix-list] NIC / Routing Tables
"M. Morgan" <[email protected]> Fri, 16 Jan 2004 16:28:56 -0500 (GMT-05:00)
| Newsgroups | gmane.linux.sentinix |
|---|---|
| Message-ID | <32046864.1074288536485.JavaMail.root@wamui02.slb.atl.earthlink.net> |
Well, I've worked with it some more and editied the routing tables to point all defualt traffic to eth1 / .31 so that part works well. The remaining problem is that eth0 (snort) is recieving packets but not transfering them to the database. Everything loads without error in snortcenter/mysql/snort but the eth0 NIC wont log alerts. eth0 is now configured as IP-0.0.0.0 / netmask 0.0.0.0 / sniffed eth1 is 192.168.1.31 / 255.255.255.0 /admin - database reporting NIC so Im thinking, do I edit the routing table and route packets from eth0 to eth1-KqHMdBRT/[email protected]? If this works is it a security risk? Hmm... I'm going to grag a bottle of merlot on the way home and revisit this system on monday. Input is always welcome :) thanks, michael This is new ground for me here and Im going to try and -----Original Message----- From: "Terkanian, Greg" <[email protected]> Sent: Jan 16, 2004 3:54 PM To: "M. Morgan" <[email protected]>, The SENTINIX Mailing List <[email protected]> Subject: RE: [sentinix-list] NIC / Routing Tables I had a similar problem on a Windows machine where I had a LAN interface, and a high-speed point to point interface, that connected to a database server (I didn't want contention when communicating with the database). I found that as soon as the server communicated with the db server, I lost LAN connectivity to it. The short story is I removed the default gateway address from the secondary interface, and it stopped trying to route traffic out it. -----Original Message----- From: sentinix-bounces-y1CeFY8bYInMlQukkHbAVdBPR1lH4CV8@public.gmane.org [mailto:sentinix-bounces-y1CeFY8bYInMlQukkHbAVdBPR1lH4CV8@public.gmane.org]On Behalf Of M. Morgan Sent: Friday, January 16, 2004 1:23 PM To: [email protected]; [email protected] Subject: [sentinix-list] NIC / Routing Tables Hello all, I've encountered a problem on my remote sensors that I cant seem to resolve. It is my intent to have 1 NIC on the sniffed network and 1 NIC on the "safe" admin network where the MySQL server resides (say .29). However, when I plug eth0 into the sniffed network I lose contact with the sensor box altogether. The reason for this seems to be that the "route table" is using eth0 by defualt for all traffic. Also, the MySQL server demands that the IP# of eth0 have database access because the machine is trying to route all traffic through eth0. I need OUTBOUND traffic routed through eth1 (it's on the same LAN as the server and for admin connectivity). I use "route" at a terminal to display the table. I havent been able to configure eth0 without an IP at all as the snortcenter "add sensor" setup seems to require one. Since I cant get it done that way I "intended" to put a LAN IP on eth0 and discard all connection attempts via iptables. Here are the specs for the NIC's: 192.168.1.30 = eth0 = marked as "interface to sniff" in snortcenter = plugged into a hostile sniffed network 192.168.1.31 = eth1 = admin NIC = plugged into trusted LAN with mysql server I'm working on modifying a table now but if anyone has pointers, examples or a way to setup the sniffed NIC without an IP# feel free to contribute. thanks, Michael _______________________________________________ SENTINIX mailing list [email protected] http://elevenprospect.com/mailman/listinfo/sentinix