WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] Re: Snort on domU

To: Dot Yet <dot.yet@xxxxxxxxx>
Subject: [Xen-users] Re: Snort on domU
From: David Edmondson <dme@xxxxxxx>
Date: Fri, 26 Jun 2009 11:09:50 +0100
Cc: xen-discuss@xxxxxxxxxxxxxxx, xen-users@xxxxxxxxxxxxxxxxxxx
Delivery-date: Fri, 26 Jun 2009 07:37:06 -0700
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
In-reply-to: <93bc4af40906251508o1d341f67w160aef549a9c24be@xxxxxxxxxxxxxx> (Dot Yet's message of "Thu, 25 Jun 2009 18:08:41 -0400")
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
References: <93bc4af40906251508o1d341f67w160aef549a9c24be@xxxxxxxxxxxxxx>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
* dot.yet@xxxxxxxxx [2009-06-25 23:08:41]
> Can anyone confirm if a xen based domU can be used for snort setup? It is
> not for commercial use, rather just SOHO use.

You can run snort in a guest, but it won't see all of the traffic from
the wire.

It gets:
    - traffic to its' MAC address,
    - traffic with the multicast bit set in the destination address.

In most cases this makes it unusable for snort.

dme.
-- 
David Edmondson, Sun Microsystems, http://dme.org

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users