Bluehost.com Web Hosting $6.95

Logging network traffic - alternatives to snort?

This is a discussion on Logging network traffic - alternatives to snort? within the Linux Networking forums, part of the Linux Forums category; Hello all, I use netfilter/iptables to safeguard my debian gateway box and currently I have a selection of -j ...


Go Back   Usenet Forums > Linux Forums > Linux Networking

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 10-06-2003
Charlie
 
Posts: n/a
Default Logging network traffic - alternatives to snort?

Hello all,
I use netfilter/iptables to safeguard my debian gateway box and currently I
have a selection of -j LOG rules to monitor traffic such as SMTP/SSH.

I would like to be able to log incoming traffic in a more advanced manner
but, unfortunately, I cannot stick a snort box in front of my gateway (for
many reasons - no spare hardware, I only have one public IP and my gateway
runs quite a few public servers).

What would anyone recommend as an alternative to snort that is an
improvement over the standard -j LOG functionality?

What I am after is a clear, concise, human-readable log that lists things
such as connection attempts on certain ports, their frequency and their
source.

TIA,
--
Charlie aka gpuk
E-mail? Remove the BLOCK to reply
Reply With Quote
  #2 (permalink)  
Old 10-07-2003
Ida Young
 
Posts: n/a
Default Re: Logging network traffic - alternatives to snort?

Packet filtering firewalls check IP addresses and ports in every packet
header. They rarely look into the data. As I know, they watch the data when
the session is ftp-related and irc-related, etc. The log they generates is
hard to read. Maybe you should look for some application gateway firewall,
such as ITShield Firewall and Sidewinder Firewall. This type of firewalls
checks the data as well as IP addresses and ports, and generates the clear
and human-readable log.

Ida Young


"Charlie" <usenetBLOCK@myrealbox.com> wrote in message
news:ih83ovkp3i4uf0ceekchera0jtmk8pmiq8@4ax.com...
> Hello all,
> I use netfilter/iptables to safeguard my debian gateway box and currently

I
> have a selection of -j LOG rules to monitor traffic such as SMTP/SSH.
>
> I would like to be able to log incoming traffic in a more advanced manner
> but, unfortunately, I cannot stick a snort box in front of my gateway (for
> many reasons - no spare hardware, I only have one public IP and my gateway
> runs quite a few public servers).
>
> What would anyone recommend as an alternative to snort that is an
> improvement over the standard -j LOG functionality?
>
> What I am after is a clear, concise, human-readable log that lists things
> such as connection attempts on certain ports, their frequency and their
> source.
>
> TIA,
> --
> Charlie aka gpuk
> E-mail? Remove the BLOCK to reply



Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 09:51 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0