Snort mailing list archives

AW: Automating Sensor Installation


From: "Poppi, Sandro" <Sandro.Poppi () wacker com>
Date: Mon, 20 May 2002 16:34:02 +0200


On Sun, 19 May 2002, Darren Young wrote:

I've been in the market for a while for a dedicated
Linux sensor distro but have not found one.

<snip>


What other distros are fairly simple to automate? I've
done RedHat before, but I really don't want all their
crap on a sensor. Just a really plain and simple
release.

Darren,

I would look more closely at RedHat's kickstart facility.  It's fairly
trivial to kickstart a RH box with say, the 2.4.18 kernel, 
snort, acid,
and postgresql/mysql.

You can add in customized shell scripts as part of the post 
install.  We
use this to setup the networking scripts, routing tables, 
ips, and such.

I do sensor installation the same way using RedHat kickstart on the same
type of hardware: One default config and you have all new sensors up and
running in less than 30 minutes. I also incorporate any RH updates and
Bastille-Linux and all other tasks to harden the sensor.

So ling,
Sandro

_______________________________________________________________
Hundreds of nodes, one monster rendering program.
Now that's a super model! Visit http://clustering.foundries.sf.net/

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: