Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Advanced » how to identify the spoof of mac address with snort?

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

how to identify the spoof of mac address with snort?


Posted by ScL on July 01, 2005 03:08:13

please something know if there is some rules to identify the spoof of mac address with snort? sorry for my english!.. tanks to all!

Posted by roesch on July 02, 2005 20:38:12

Try the arpspoof preprocessor, look in the snort.conf file for information on activating and configuring it.

-Marty