arpwatch and snort help

From: Jason Benway (benwayj_at_nospam.ghsp.com.removethis)
Date: 12/20/04


Date: Mon, 20 Dec 2004 10:19:54 -0500

I setup my first linux box last week.

Its running Fedora core 3.

When I set it up I only had 1 NIC. it is on our main subnet.

I installed a second NIC and I was able to get it working. I've setup the
second nic on a mirroreds switch port so it can see traffice on 4 of our
VLANS (each VLAN is on a different subnet)

I would like to setup arpwatch to only use the second NIC and for it to
alert me to traffic on all VLANs.

I've seen the -n switch for arpwatch, but how do I use that when arpwatch is
running as a service?

How do I use the -n switch when the subnets are not together (example:
10.0.0.1,192.168.1.1,192.168.42.1)

I would also like to setup snort to only listen on the second NIC

Thank you
jb



Relevant Pages

  • Re: arpwatch and snort help
    ... > I setup my first linux box last week. ... > second nic on a mirroreds switch port so it can see traffice on 4 of ... > alert me to traffic on all VLANs. ... As far as snort and vlan monitoring are concerned, ...
    (comp.os.linux.security)
  • RE: FREEBSD between two trunks
    ... There was an old funny thing about bridging vlans: ... > I'm trying to setup DUMMYNET to emulate long delays, ... freebsd host between two trunks passing vlans. ...
    (freebsd-net)
  • VLANS in a DMZ - good idea?
    ... I am looking to setup a new perimeter network for a client and am ... VLANS setup on the switch and equally Firewall 2 will only allow ...
    (comp.security.firewalls)
  • Re: Sharing Internet Connection Across Vlans
    ... I'm trying to set up multiple vlans at work and I'm fairly new to IOS. ... The router is setup with virtual interfaces so I have: ... interface FastEthernet0/1.1 ...
    (comp.dcom.sys.cisco)
  • 802.1q VLAN tagging
    ... the communications to the other VLANs did not. ... The trunk ports have been setup for 802.1q between the switches and the ... ports for this sun server is also setup as a 802.1q trunk. ... So I am pretty sure that my switch configuration is ...
    (SunManagers)

Quantcast