Snort mailing list archives

Re: Linux distro for Snort inline as IPS


From: wkitty42 () windstream net
Date: Tue, 26 Jan 2016 08:45:29 -0500

On 01/25/2016 09:47 PM, Jeff H wrote:
I don't think Security Onion would be a good fit. Inline IPS mode isn't
supported and it has quite a bit of additional NSM software running by
default that would need to be disabled if only Snort is required.

I'm not aware of any specific stripped down distros for running Snort inline,
I would start with a well supported minimal Linux distro and add what is
needed.

i agree with this... not only a well supported distro but one with long term 
support, too... you do not want a rolling bleeding edge to deal with in addition 
trying to stay up on network security...

-- 
  NOTE: No off-list assistance is given without prior approval.
        *Please keep mailing list traffic on the list* unless
        private contact is specifically requested and granted.

------------------------------------------------------------------------------
Site24x7 APM Insight: Get Deep Visibility into Application Performance
APM + Mobile APM + RUM: Monitor 3 App instances at just $35/Month
Monitor end-to-end web transactions and take corrective actions now
Troubleshoot faster and improve end-user experience. Signup Now!
http://pubads.g.doubleclick.net/gampad/clk?id=267308311&iu=/4140
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://sourceforge.net/mailarchive/forum.php?forum_name=snort-users

Please visit http://blog.snort.org to stay current on all the latest Snort news!


Current thread: