Snort Issues

This section introduces some of the most common troubleshooting questions encountered when working with Snort. If you cannot find the answer to your issue here, check the online mailing lists. Here is some introductory troubleshooting advice you can use when working with Snort:

How Do I Run Snort on Mutiple Interfaces?

Snort can be configured to listen on more than one NIC. The problem is that Snort accepts only one interface switch (-i) per command line. There are two methods of running Snort on multiple interfaces: one is to run a separate Snort process for each interface, and the other is to bond the interfaces together by using the bonding feature of the Linux kernel.

Choosing the best method of monitoring several interfaces ...

Get Intrusion Detection with Snort now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.