Snort mailing list archives

Doubt about configuration HOME, EXTERNAL.


From: Agus <agus.262 () gmail com>
Date: Tue, 4 Jun 2013 13:36:34 -0300

Hi guys,

I have a subnet that connects to a client Network. They asked me to
implement an IDS. Si i built snort/snorby/PP

This is an unusual, at least for me, place as i am supposed to monitor the
traffic going away from my net to the other, instead of what it is more
common that i monitor incoming traffic to my severs.

So my doubt is how should i configure the Network variables.

My net = 10.11.0.0/24 - HOME_NET
Client = !HOME_NET - EXTERNAL_NET

That is the approach i took. the same as if the servers were on my net; but
that aint the case as i have the clients/users on my NET, and all
services(web, proxy, inet) are on their side. I was thinking on swapping
the values.

Thanks for any tip you can provide!
Cheers
------------------------------------------------------------------------------
How ServiceNow helps IT people transform IT departments:
1. A cloud service to automate IT design, transition and operations
2. Dashboards that offer high-level views of enterprise services
3. A single system of record for all IT processes
http://p.sf.net/sfu/servicenow-d2d-j
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Current thread: