Snort mailing list archives

Re: Snort Deployment Configurations


From: Martin Holste <mcholste () gmail com>
Date: Thu, 3 Feb 2011 21:11:14 -0600

What other considerations might someone new to snort such as myself overlook
at first thought?


I currently run Snort in multiple configurations on the gateway, but I
used to run it between servers and clients in the data center.  This
proved to be a total waste of time--the amount of traffic that needs
to be inspected combined with the massive amount of false positives
proved to be ineffective for useful intel for the amount of effort
required.  For monitoring the inside of the network, I recommend a
strategy of Netflow, firewall logs, and server logs before you start
trying IDS on that amount and kind of traffic.

------------------------------------------------------------------------------
The modern datacenter depends on network connectivity to access resources
and provide services. The best practices for maximizing a physical server's
connectivity to a physical network are well understood - see how these
rules translate into the virtual world? 
http://p.sf.net/sfu/oracle-sfdevnlfb
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: