Snort mailing list archives

TCP Syn performance test


From: Jaime Nebrera <jnebrera () gmail com>
Date: Thu, 26 Jul 2012 14:40:42 +0200

   Hi all,

   We are trying to test the performance of Snort running as IPS using a 
TCP Syn Flood (sadly, dont have statefull tester right now)

   For sure Snort is not liking this kind of traffic (it didnt complain 
at all when done using UDP traffic) and some preprocessor is dropping 
the traffic, thus the generator believes is loosing traffic.

   May I ask what is the recommended procedure to configure Snort for 
such test? (of course, wont be a secure test, just performance wise)

   Thanks in advance. Regards

------------------------------------------------------------------------------
Live Security Virtual Conference
Exclusive live event will cover all the ways today's security and 
threat landscape has changed and how IT managers can respond. Discussions 
will include endpoint security, mobile security and the latest in malware 
threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
_______________________________________________
Snort-devel mailing list
Snort-devel () lists sourceforge net
https://lists.sourceforge.net/lists/listinfo/snort-devel

Please visit http://blog.snort.org for the latest news about Snort!


Current thread: