Snort.org home  
Got Source? About Snort About Sourcefire Snort FAQ
Sourcefire Network Security - the creators of Snort

Snort Forums Archive

Archive Home » Snort Advanced » redundant FW usining .1q trunk

Please note that the categories listed below represent an archived version of our forums pages. To view the current version and be able to post and reply to threads, please register and login here to go to the full forums pages.

[ Notice: Full Version of This Topic ]

redundant FW usining .1q trunk


Posted by snortng on July 13, 2005 00:48:09

Hi,

how can i use snort on a single mascine with two network interfaces to monitor my HA segment?

Checkpoint using .1q trunk------- IDS eth0 --------- DMZ1
Checkpoint using .1q trunk------- IDS eth1 --------- DMZ1

thanks in advance

Posted by Joel_Esler on August 30, 2005 10:43:43

Run two different instances of Snort, listening on two different interfaces. Look into the "-i" option.

Joel Esler
SOURCEfire