[Bro] Monitor the traffic form interface and pass it to other interface

Vern Paxson vern at icir.org
Fri Mar 6 12:50:45 PST 2009


> How can I make Bro IDS monitor and analyze all the traffic come from eth0?

Use
	redef interfaces = "eth0";

in you policy script, or "bro -i eth0 ..." when you execute Bro.

> And after that pass the traffic to eth1?

Bro doesn't have a packet forwarding capability for inline operation.

		Vern



More information about the Bro mailing list