Snort mailing list archives
Snort Placement
From: "Paul Ryan" <pryan () rogers wave ca>
Date: Sat, 9 Oct 2004 15:48:26 -0400
I was hoping to get input on the best placement of my snort box. This box is to be used to track traffic to the Internet from my corporate LAN. The traffic traverses a PIX before hitting the Internet, subsequently all outside destined traffic is NAT'd to one public IP. If I place on the outside of the firewall - all source IP's are the NAT, which is useless is tracking offenders on my LAN. Placing it before the PIX - brings up some challeges ... The PIX has a Inside, DMZ and Outside interface. What do u think ? Regards, paul ------------------------------------------------------- This SF.net email is sponsored by: IT Product Guide on ITManagersJournal Use IT products in your business? Tell us what you think of them. Give us Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more http://productguide.itmanagersjournal.com/guidepromo.tmpl _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort Placement Paul Ryan (Oct 09)
- Re: Snort Placement Jose Maria Lopez (Oct 10)
- Re: Snort Placement Paul Halliday (Oct 10)
- <Possible follow-ups>
- Re: Snort Placement Shawn Kottke (Oct 09)
- Re: Snort Placement Jose Maria Lopez (Oct 10)