Snort mailing list archives

Attack on snort running in Public Zone


From: "KS" <kanwaljeet () emind com>
Date: Mon, 10 Nov 2003 20:48:11 +0530

Helllo Everybody.

I have snort running on win2k and it is working fine so far.I had placed it
in DMZ to monitor the malicious traffic passing through firewall and Now i
want to put another snort win2k system in Public zone i.e in between my
router and firewall so i can know which traffic is actually hitting the
outside interface of my firewall.
My concern is :  Since my snort system ( win2k ) is gonna be on public IP
address , what will happen if somebody runs a Denial of service attack on my
snort system itself.
How can i be sure that my snort system running on win2k is safe from DOS
attack ?

Thanks
KS

Current thread: