Snort mailing list archives

RE: snort deployment


From: "Patrick Harper" <patrick () internetsecurityguru com>
Date: Mon, 29 Aug 2005 20:56:19 -0500

I would set up a span port personally, most modern switch's will do it, even
my cheapo gig managed switched from Dell. Other wise I guess you could do a
bridge but I would suggest you get a hub or a cheap managed switch.  That is
just my personal opinion.



Patrick S. Harper | CISSP RHCT MCSE
www.internetsecurityguru.com

Just because your paranoid, doesn't mean they're not out to get you 




 
-----Original Message-----
From: snort-users-admin () lists sourceforge net
[mailto:snort-users-admin () lists sourceforge net] On Behalf Of fname lname
Sent: Monday, August 29, 2005 8:22 PM
To: snort-users () lists sourceforge net
Subject: [Snort-users] snort deployment

Im building a linux box with to nics  I want to put this box between my pix
and switch. So I can for the IDS on all that traffic coming in and out of
our lan.  I wanted to know should I setup this up in a bridge mode because I
dont have a tap.

Thanks adv.





-------------------------------------------------------
SF.Net email is Sponsored by the Better Software Conference & EXPO
September 19-22, 2005 * San Francisco, CA * Development Lifecycle Practices
Agile & Plan-Driven Development * Managing Projects & Teams * Testing & QA
Security * Process Improvement & Measurement * http://www.sqe.com/bsce5sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: