Why not simply put a $45 router in place of the hub? This way, you can be seen as a single IP to your ISP and you can set a static RCF1918 addy to your snort box behind the router, or, you can throw it into a DMZ between the ISP and the inside network. You have many options here. The rest of your hosts can grab a DHCP address from the router and life is wonderful in smallville.
Don't get hung up on sniffing w/o an IP. The power is in simplicity.
![]()




Reply With Quote