Snort mailing list archives

Re: Snort in a cluster


From: Michael Stone <mstone+snort () mathom us>
Date: Mon, 12 Jul 2004 06:38:09 -0400

On Mon, Jul 12, 2004 at 09:52:14AM +0100, Alex Butcher, ISC/ISYS wrote:
Or you can adjust the pcap filter so snort sees less traffic.

Out of interest, how do you divide up the traffic? TCP vs. UDP? ports 0-32767 vs 32768-65535? Or some other way?

Anyway that makes sense for your environment. Some I divide by port,
some by ip range. It's enough on some systems just to do 80 and !80.

I've had good success running multiple snorts on one system where each
sees part of the traffic and together they can keep up with a faster link than a single process trying to watch everything.

I won't deny your experience, but that doesn't make much sense! *shrug*

It doesn't make sense that dividing a traffic stream in half and giving
each half its own processor allows more traffic to be monitored than
trying to watch the same traffic with a single processor?

Mike Stone


-------------------------------------------------------
This SF.Net email sponsored by Black Hat Briefings & Training.
Attend Black Hat Briefings & Training, Las Vegas July 24-29 - digital self defense, top technical experts, no vendor pitches, unmatched networking opportunities. Visit www.blackhat.com
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: