Snort mailing list archives
LAN
From: "snortlst snortlst" <snortlst () hotmail com>
Date: Tue, 6 Nov 2001 10:01:29 -0500
I run snort as ids.I have a sensor on LAN that sniffs traffic coming inside our lan from firewall's lan interface. Is that enough to figure out if there are some trojans running on some workstations on the lan, or some other problems with lan wstations? (I thought it would be enough to see the traffic on fw lan interface cause even if there are some trojans on workstations it'll go to the fw lan int. anyway cause it is a default gw for lan wstations. Just wanted to veryfy that....) If this configuration is not enough then what.....I should mirror all 700 ports on the lan switch to the snort sensor port? thx. _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- LAN snortlst snortlst (Nov 06)
- Re: LAN Jason Costomiris (Nov 06)