Snort mailing list archives

Re: Snort Placement


From: "Shawn Kottke" <skottke () datalink com>
Date: Sat, 9 Oct 2004 17:08:34 -0500

Either get two and place one on the inside and one in the dmz. Or use one with three nics where one nic is capturing 
inside and one is capturing dmz and the last is for controlling. Or depending on the importance of the dmz do not 
capture there - this depends on the risk you are willing to take and able to accept. 





-----Original Message-----
From: snort-users-admin () lists sourceforge net <snort-users-admin () lists sourceforge net>
To: snort-users () lists sourceforge net <snort-users () lists sourceforge net>
Sent: Sat Oct 09 14:48:26 2004
Subject: [Snort-users] Snort Placement

I was hoping to get input on the best placement of my snort box.

This box is to be used to track traffic to the Internet from my corporate
LAN. The traffic traverses a PIX before hitting the Internet, subsequently
all outside destined traffic is NAT'd to one public IP.

If I place on the outside of the firewall - all source IP's are the NAT,
which is useless is tracking offenders on my LAN.
Placing it before the PIX - brings up some challeges ...

The PIX has a Inside, DMZ and Outside interface.

What do u think ?

Regards,

paul




-------------------------------------------------------
This SF.net email is sponsored by: IT Product Guide on ITManagersJournal
Use IT products in your business? Tell us what you think of them. Give us
Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more
http://productguide.itmanagersjournal.com/guidepromo.tmpl
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users

Current thread: