LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 04-09-2009, 09:13 AM   #1
priyadarshan
Member
 
Registered: Feb 2009
Location: Ahmedabad, Gujarat, India
Posts: 197

Rep: Reputation: Disabled
Question Snort


Atlast I got my snort running in inline mode......

But now a new kinda problem is there

I am running linux on VMplayer and I have configured

eth0 as 192.168.1.9
and
eth1 as 10.10.135.22

I use windows browser to check anything developed in linux
For example,

By implementing IPTable srules I try to put 192.168.1.9 or 10.10.135.22 in browser in windows... and so....

Now I have configured IPTables for snort_inline as below-

Chain INPUT
target prot opt in out source destination

QUEUE all - eth0 * 0.0.0.0/0 0.0.0.0/0

QUEUE all - eth1 * 0.0.0.0/0 0.0.0.0/0

Chain Forward
Nothing here

Chain OUTPUT
target prot opt in out source destination

QUEUE tcp - * * 0.0.0.0/0 0.0.0.0/0
tcp dpt:80


and there is nothing in local.rules file...........

But when I get snort run or not

There nothing comes in responce....
 
Old 04-09-2009, 09:39 AM   #2
priyadarshan
Member
 
Registered: Feb 2009
Location: Ahmedabad, Gujarat, India
Posts: 197

Original Poster
Rep: Reputation: Disabled
I got the things working..... at last

I needed to write

QUEUE tcp - * * 0.0.0.0/0 0.0.0.0/0
tcp spt:80

instead of

QUEUE tcp - * * 0.0.0.0/0 0.0.0.0/0
tcp dpt:80

in my case................................
 
Old 04-09-2009, 11:47 AM   #3
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
priyadarshan, you continue posting all your Snort questions here in Security even though you see they keep being moved to Software. Please stop doing that. Look, if your issue is that you can't get Snort to work properly, that's a software question - not a security one. It doesn't matter whether Snort is a security tool or not.

Moved to Software.
 
Old 04-10-2009, 01:33 AM   #4
priyadarshan
Member
 
Registered: Feb 2009
Location: Ahmedabad, Gujarat, India
Posts: 197

Original Poster
Rep: Reputation: Disabled
OKOKOK sorry.....
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[HELP]SNORT PROBLEMS(IDS)-service snort start JayCool Linux - Software 5 03-15-2009 12:34 PM
Snort - no portscan and tcp alerts in snort av.dubey Linux - Software 6 07-11-2008 09:56 PM
Starting snort: ERROR: User "snort" unknown games1 Linux - Software 3 02-07-2007 08:21 PM
Error when starting up snort: bash:!/bin/sh/usr/local/bin/snort :Eent not found cynthia_thomas Linux - Software 1 11-11-2005 02:59 PM
snort failed: snort: symbol lookup error: undefined symbol: usmAES192PrivProtocol Emmanuel_uk Linux - Security 1 07-10-2005 10:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 07:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration