The arrow flips down, and you get a menu of different categories under the Mail & Newsgroups listing. 6. The options are: -i interface, -n packet count, -v verbose. # snort -i eth1 -n 5 -v Log directory = --== Initializing Snort ==-Initializing Network Interface eth1 Decoding Ethernet on interface eth1 --== Initialization Complete ==--*> Snort! <*Version 1.8.1-RELEASE (Build 74) By Martin Roesch (roesch@sourcefire.com, www.snort.org) 09/10-11:54:04.219707 nn.m.192.223:61411 -> xx.yyy.213.167:554 TCP TTL:63 TOS:0x0 ID:41861 IpLen:20 DgmLen:40 DF ***A**** Seq: 0x218D4793 Ack: 0x9B5297 Win: 0x3EBC TcpLen: 20 =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ 09/10-11:54:04.309707 xx.yyy.213.167:554 -> TCP TTL:114 TOS:0x0 ID:37855 IpLen:20 DgmLen:694 DF ***AP*** Seq: 0x9B5297 Ack: 0x218D4793 Win: 0x1E56 TcpLen: 20 =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ 09/10-11:54:04.329707 nn.m.192.223:61411 -> xx.yyy.213.167:554 TCP TTL:63 TOS:0x0 ID:41862 IpLen:20 DgmLen:40 DF ***A**** Seq: 0x218D4793 Ack: 0x9B5525 Win: 0x3C2E TcpLen: 20 =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ 09/10-11:54:04.409707 xx.yyy.213.167:554 -> TCP TTL:114 TOS:0x0 ID:14816 IpLen:20 DgmLen:694 DF ***AP*** Seq: 0x9B5525 Ack: 0x218D4793 Win: 0x1E56 TcpLen: 20 =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ 09/10-11:54:04.409707 nn.m.192.223:61411 -> xx.yyy.213.167:554 TCP TTL:63 TOS:0x0 ID:41863 IpLen:20 DgmLen:40 DF ***A**** Seq: 0x218D4793 Ack: 0x9B57B3 Win: 0x39A0 TcpLen: 20 =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ =============================================================================== Snort analyzed 5 out of 5 packets, dropping 0(0.000%) packets Breakdown by protocol: TCP: 5 UDP: 0 ICMP: 0 ARP: 0 IPv6: 0 IPX: 0 OTHER: 0 DISCARD: 0 (100.000%) (0.000%) (0.000%) (0.000%) (0.000%) (0.000%) (0.000%) (0.000%) Action Stats: ALERTS: 0 LOGGED: 0 PASSED: 0 =============================================================================== Fragmentation Stats: Fragmented IP Packets: 0 Fragment Trackers: 0 Rebuilt IP Packets: 0 Frag elements used: 0 Discarded(incomplete): 0 Discarded(timeout): 0 Frag2 memory faults: 0 =============================================================================== TCP Stream Reassembly Stats: TCP Packets Used: 0 Stream Trackers: 0 (0.000%) (0.000%) Stream flushes: 0 Segments used: 0 Stream4 Memory Faults: 0 =============================================================================== Snort received signal 3, exiting The term firewall has suffered the fate of most creatures who gain too much popularity; it has become, if not debased, at least muddied as to its meaning.

