1 |
Hello, |
2 |
|
3 |
For a variety of reasons, I need to be able to make an ethernet |
4 |
interface on a gentoo system, change into listen only (stealth mode). |
5 |
Kind of like half duplex, so to speak. Any simple tricks? |
6 |
Just disabling all responses from the ethernet interface would do. |
7 |
I know I can just use 'ifconfig eth0 down' but anything more |
8 |
elegant or that would allow the interface to keep receiving |
9 |
packets for analysis and logging would be better. |
10 |
|
11 |
At other times I need to run a full blown IDS, like snort, |
12 |
on an ethernet port, but without being externally detected. |
13 |
What would be best method (tools) to ensure the interface is actually |
14 |
not detectable on a given lan segment? |
15 |
Here is a good (Redhat) but old link that kind of outlines the idea: |
16 |
|
17 |
http://www.linuxjournal.com/article/6222 |
18 |
|
19 |
Any web pages, documents or information that is more current and |
20 |
gentoo specific would be of greatly appreciated. |
21 |
|
22 |
TIA, |
23 |
|
24 |
James |
25 |
|
26 |
-- |
27 |
gentoo-user@g.o mailing list |