Snort mailing list archives
Re: Snort in a cluster
From: Michael Stone <mstone+snort () mathom us>
Date: Mon, 12 Jul 2004 06:38:09 -0400
On Mon, Jul 12, 2004 at 09:52:14AM +0100, Alex Butcher, ISC/ISYS wrote:
Or you can adjust the pcap filter so snort sees less traffic.Out of interest, how do you divide up the traffic? TCP vs. UDP? ports 0-32767 vs 32768-65535? Or some other way?
Anyway that makes sense for your environment. Some I divide by port, some by ip range. It's enough on some systems just to do 80 and !80.
I've had good success running multiple snorts on one system where eachsees part of the traffic and together they can keep up with a faster link than a single process trying to watch everything.I won't deny your experience, but that doesn't make much sense! *shrug*
It doesn't make sense that dividing a traffic stream in half and giving each half its own processor allows more traffic to be monitored than trying to watch the same traffic with a single processor? Mike Stone ------------------------------------------------------- This SF.Net email sponsored by Black Hat Briefings & Training.Attend Black Hat Briefings & Training, Las Vegas July 24-29 - digital self defense, top technical experts, no vendor pitches, unmatched networking opportunities. Visit www.blackhat.com
_______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Snort in a cluster Luis Claudio Rodrigues da Silveira (Jul 09)
- Re: Snort in a cluster Alex Butcher, ISC/ISYS (Jul 09)
- Re: Snort in a cluster Michael Stone (Jul 09)
- Message not available
- Re: Snort in a cluster Michael Stone (Jul 12)
- Re: Snort in a cluster Alex Butcher, ISC/ISYS (Jul 15)
- Re: Snort in a cluster Michael Stone (Jul 09)
- Re: Snort in a cluster Alex Butcher, ISC/ISYS (Jul 09)
- <Possible follow-ups>
- RE: Snort in a cluster Williams Jon (Jul 09)
- Re: Snort in a cluster Jason (Jul 09)
- RE: Snort in a cluster Joshua Berry (Jul 09)
- Re: Snort in a cluster Jason (Jul 09)
- Re: Snort in a cluster Michael Stone (Jul 09)