Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Windows » snort running on machine A monitoring web server B...how?

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

snort running on machine A monitoring web server B...how?


Posted by gangelo on June 24, 2006 16:30:22

I am running snort on a w2003 server machine (A) and want to monitor my w2003 web server (B). snort does not seem to pick up any web traffic on B. In the config file, I set machine B to handle http requests. Can someone help me with this configuration, or do I need to post more information?

Thanks.

Posted by MJM on July 25, 2006 09:23:22

Talk to your network folks. As a rule, Snort only sees traffic (unicast, multicast, broadcast) directed to the machine it is running on. If you are in a switched environment, your Snort machine is seeing only traffic in its "collision domain". A sniffer on a machine connected to a switch port sees only that port's traffic. There are options: the legitimate ones require working with your network folks. You can also try MAC floods and ARP poisoning, but those are "loud" attacks, they will probably fail (if you have a newer switch), and they may cause crashes and other denials of service.