[prev in list] [next in list] [prev in thread] [next in thread] 

List:       bro
Subject:    Re: [Bro] Monitor the traffic form interface and pass it to other interface
From:       Nasiriyah Iraq <inasiriyah () yahoo ! com>
Date:       2009-03-25 17:58:27
Message-ID: 630202.12403.qm () web59713 ! mail ! ac4 ! yahoo ! com
[Download RAW message or body]

Hello
 
Thank you for replay
Actualy I want to use Bro as Intrusion Prevention System, and I  want to know which \
processors or options which affect the delay time?  
With regards
 
Kaled Azrane
 


--- On Sat, 3/7/09, jean-philippe luiggi <jean-philippe.luiggi@didconcept.com> wrote:

From: jean-philippe luiggi <jean-philippe.luiggi@didconcept.com>
Subject: Re: [Bro] Monitor the traffic form interface and pass it to other interface
To: "Nasiriyah Iraq" <inasiriyah@yahoo.com>
Cc: bro@ICSI.Berkeley.EDU
Date: Saturday, March 7, 2009, 8:02 PM

Hello,

I'm not (yet) sure of what's your exact setup but Bro acts as a
"viewer" and
is unable to inject data.
Now about your need, if you want to get packets on eth0 and just forward
them to eth1, you may use firewall's rules.

With regards,

Jean-Philippe.

* Nasiriyah Iraq <inasiriyah@yahoo.com> [2009-03-06 05:08:16 -0800]:

> Dear all
> I have server with Ubuntu 8.10 operating system and Bro Ids 1.4, and there
are two network interfaces installed in this server eth0 and eth1.
> The interface eth0 connected to the internet, and the interface eth1
connected to my special local area network.
> How can I make Bro IDS monitor and analyze all the traffic come from eth0?
And after that pass the traffic to eth1?
  



      


[Attachment #3 (text/html)]

<table cellspacing="0" cellpadding="0" border="0" ><tr><td valign="top" style="font: \
inherit;"><DIV>Hello</DIV> <DIV>&nbsp;</DIV>
<DIV>Thank you for replay</DIV>
<DIV>Actualy I want to use Bro as Intrusion Prevention System, and I&nbsp; want to \
know which processors or options which affect the delay time?</DIV> <DIV>&nbsp;</DIV>
<DIV>With regards</DIV>
<DIV>&nbsp;</DIV>
<DIV>Kaled Azrane</DIV>
<DIV>&nbsp;</DIV>
<DIV><BR><BR>--- On <B>Sat, 3/7/09, jean-philippe luiggi \
<I>&lt;jean-philippe.luiggi@didconcept.com&gt;</I></B> wrote:<BR></DIV> <BLOCKQUOTE \
style="PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: rgb(16,16,255) 2px \
solid">From: jean-philippe luiggi \
&lt;jean-philippe.luiggi@didconcept.com&gt;<BR>Subject: Re: [Bro] Monitor the traffic \
form interface and pass it to other interface<BR>To: "Nasiriyah Iraq" \
&lt;inasiriyah@yahoo..com&gt;<BR>Cc: bro@ICSI.Berkeley.EDU<BR>Date: Saturday, March \
7, 2009, 8:02 PM<BR><BR><PRE>Hello,

I'm not (yet) sure of what's your exact setup but Bro acts as a
"viewer" and
is unable to inject data.
Now about your need, if you want to get packets on eth0 and just forward
them to eth1, you may use firewall's rules.

With regards,

Jean-Philippe.

* Nasiriyah Iraq &lt;inasiriyah@yahoo.com&gt; [2009-03-06 05:08:16 -0800]:

&gt; Dear all
&gt; I have server with Ubuntu 8.10 operating system and Bro Ids 1.4, and there
are two network interfaces installed in this server eth0 and eth1.
&gt; The interface eth0 connected to the internet, and the interface eth1
connected to my special local area network.
&gt; How can I make Bro IDS monitor and analyze all the traffic come from eth0?
And after that pass the traffic to eth1?
 &nbsp;
</PRE></BLOCKQUOTE></td></tr></table><br>

      



[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic