This is a discussion on Re: [Snort-users] How to setup inline within the Snort forums, part of the System Security and Security Related category; What distro are you thinking about using? If you do not wish to reply to the list with this information, ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
What distro are you thinking about using? If you do not wish to reply
to the list with this information, you can reply to me off-list and I would be glad to point you in the right direction. Possibly help you avoid some distro related road bumps. Regards, Will On 4/7/06, Mike Montgomery <mmontgomery@c3bb.com> wrote: > Hello, > > I recently setup a box running snort at our headend, its not inline as > of now, but its using a monitor port on a cisco 2950. What would be the > ideal setup to put the box inline? I currently have 2 nics in this box, > 1 on the monitor port, 2nd is the nic I use to connect to the box for > console. To go inline, would I need 3 nics total, 1 in, 1 out, and set > them to be bridged? Or what. If I wanted snort to drop the packets for > say P2P, would snort do that by itself, or would I need to have a > firewall running to do that. Just trying to make some sense of this. > > Thanks > > Mike Montgomery > Citizens Communications Corp. > /Systems Administrator/ > > > ------------------------------------------------------- > This SF.Net email is sponsored by xPML, a groundbreaking scripting langua= ge > that extends applications into web and mobile media. Attend the live webc= ast > and join the prime developer group breaking into this new coding territor= y! > http://sel.as-us.falkag.net/sel?cmd=...=3D241720&dat= =3D121642 > _______________________________________________ > Snort-users mailing list > Snort-users@lists.sourceforge.net > Go to this URL to change user options or unsubscribe: > https://lists.sourceforge.net/lists/...fo/snort-users > Snort-users list archive: > http://www.geocrawler.com/redir-sf.p...=3Dsnort-users > ------------------------------------------------------- This SF.Net email is sponsored by xPML, a groundbreaking scripting language that extends applications into web and mobile media. Attend the live webcast and join the prime developer group breaking into this new coding territory! http://sel.as-us.falkag.net/sel?cmd=...720&dat=121642 _______________________________________________ Snort-users mailing list Snort-users@lists.sourceforge.net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/...fo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.p...st=snort-users |