Snort mailing list archives

LAN


From: "snortlst snortlst" <snortlst () hotmail com>
Date: Tue, 6 Nov 2001 10:01:29 -0500

I run snort as ids.I have a sensor on LAN that sniffs traffic coming inside
our lan from firewall's lan interface. Is that enough to figure out if there
are some trojans running on some workstations on the lan, or some other
problems with lan wstations?
(I thought it would be enough to see the traffic on fw lan interface cause
even if there are some trojans on workstations it'll go to the fw lan int.
anyway cause it is a default gw for lan wstations. Just wanted to veryfy
that....)

If this configuration is not enough then what.....I should mirror all 700
ports on the lan switch to the snort sensor port?

thx.


_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: