Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Newbies » Configuration doubts

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

Configuration doubts


Posted by mangood on March 19, 2005 14:46:19

Hi
I hope you can help me :) I'm going to place SNORT in my DMZ, unfortunatelly I'm running out of ip numbers. So basicaly I want to know If I have to configure interface connected to this DMZ with legal ip address. Or maybe it's better not to configure it at all - from security reasons ? What do you think ??
Thanks in advance.

Posted by roesch on March 19, 2005 17:16:29

Check out section 3.1 of the FAQ, it has your answer.

Basically you want to "stealth" the sniffing interface of the Snort process, it doesn't need to have an IP address in order to sniff.

-Marty