Snort mailing list archives

Using SNORT for Internal IDS


From: "Pankaj Gupta" <pgupta () interloci com>
Date: Tue, 24 Jun 2003 16:16:50 -0400

I am not sure if Snort can be used to monitor internal attacks or intrusion
activities. Also, can I use two copies of Snort (installed on two separate
servers), one to monitor the external port outside my firewall and the other
to monitor specific internal ports for signature matches. Does anyone have
any experience, inputs or documentation on this matter? Thanks.

Pankaj Gupta


Current thread: