|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: [Snort-users] 2 class C network
From: Jeff (jcoppock1
comcast.net)
Date: Thu Jan 29 2004 - 15:39:17 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Greg Chu, 2004-Jan-22 16:51 -0500:
> Hi,
> I need help to sniffer two class C network
>
> network 1 connect to network 2 through a cisco router
> my servers are on network 1. my network 2 connect to around 150 users.
> if I put snort on one of the server on network 1, then I only see traffic
> logged on network 1.
>
> My question is how can I see traffice on network 2 which is interfaced
> through the router.
>
> all traffice to network 2 is routed to the ip of the ethernet 0 on the
> router.
>
> Or I have to put snort on network 2 to see the traffic.
>
> When I install snort on 1 pc on network 2, which is a xp machine, it says
> wincap can not find host name.
>
> Any help is appreciated.
>
> Thanks!
> Greg
Any sniffing of traffic requires physical access to the network to be
sniffed (or snorted). You'll have to put a system on network 2 in
order to see that traffic.
jc
--
Jeff Coppock Systems Engineer
Diggin' Debian Admin and User
-------------------------------------------------------
The SF.Net email is sponsored by EclipseCon 2004
Premiere Conference on Open Tools Development and Integration
See the breadth of Eclipse activity. February 3-5 in Anaheim, CA.
http://www.eclipsecon.org/osdn
_______________________________________________
Snort-users mailing list
Snort-users
lists.sourceforge.net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]