Security Basics mailing list archives

Passive Snort Setup


From: Daniel Hood <dsmhood () gmail com>
Date: Fri, 20 Feb 2009 11:19:08 +1100

Is it possible to set up a Snort IDS system with a topology like this:

hosts > switch > Snort-IDS > Router

But, have no ip address on either interface of the snort box and it
just forward packets through after checking them for malicious
activity? I don't want the snort box to do NAT or be the default
gateway, I just want it to passively be there.

Daniel


Current thread: