
304
WindoWs netWorking tools
type, the file can be opened using Word. In fact, Figure8.5 illustrates
the first of 11 pages of the snort.conf file. While we will defer discuss-
ing this file until later in this chapter, remember its location.
8.1.3 Commencing Snort
Snort can operate in three modes, referred to as sniffer mode, packet
logger mode, and Network Intrusion Detection System (NIDS)
mode. In the sniffer mode of operation snort continuously reads pack-
ets on the network and displays them in a continuous stream. In the
packet logger mode packets are logged to disk, while in the NIDS
mode Snort will analyze packets against user-defined rules. As ...