RE: Snort sensor placement
From: George Milliken (gmilliken@farm9.com)Date: 09/27/01
- Previous message: Thiago Conde Figueiro: "Re: Snort sensor placement"
- In reply to: Tom Lichti: "RE: Snort sensor placement"
- Next in thread: Dave Vehrs: "RE: Snort sensor placement"
- Next in thread: Lee Binette: "Re: Snort sensor placement"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "George Milliken" <gmilliken@farm9.com> To: "Tom Lichti" <tom@redpepperracing.com>, <focus-ids@securityfocus.com> Subject: RE: Snort sensor placement Date: Thu, 27 Sep 2001 08:45:43 -0700 Message-ID: <NFBBIHEDEKGKIEDFMMMBOELFCCAA.gmilliken@farm9.com>
Hub between FW and cable modem, that way you see attacks that will not make
it thru the FW, thus you see what people are doing to the FW.
George
farm9
-----Original Message-----
From: Tom Lichti [mailto:tom@redpepperracing.com]
Sent: Thursday, September 27, 2001 7:57 AM
To: focus-ids@securityfocus.com
Subject: RE: Snort sensor placement
Here's a question along the same lines. This is my current setup:
---------- ----------- ---------- -------- -----------
| INTERNET |--| CBL MODEM |--| FIREWALL |----| SWITCH |----| SERVER(S) |
---------- ----------- ---------- -------- -----------
I have at my disposal a spare hub (2 actually), and possibly a spare
machine to run Snort. One caveat is the switch is very basic, with no
spanning or mirroring ports. Here are the scenarios:
1) Install Snort on an existing machine, either the firewall or the main
server. If so, which would be the best choice? FW is running OpenBSD 2.8,
server is RH 7.1.
2) Install the hub and the spare machine running snort, similar to the
diagram below. Where should the hub go? And what OS would be the choice for
the machine running Snort? It won't be a very fast machine (P300'ish), with
as much RAM as I can stuff onto the MB. Would it be possible to put it in
front of the firewall?
Thanks for any input.
Tom
--On Friday, September 21, 2001 9:55 AM -0600 Dave Vehrs
<davev@spiremedia.com> wrote:
>
> Close but what is the small hub connecting to? If its another hub then
> you will see all the traffic from it too.
>
> What I would do is this:
>
> ----- -------- ----------- --------
>| LAN |----| SWITCH |----| SMALL HUB |----| SERVER |
> ----- -------- ----------- --------
> |
> (receive only cable)->|
> |
> -------
> | SNORT |
> -------
>
> You can find information on how to build at receive only network cable at:
> http://personal.ie.cuhk.edu.hk/~msng0/sniffing_cable/
>
> Then I would either manage the Snort sensor directly from its own
> monitor/keyboard or add a second "management" interface to connect back
> to a secure location on the LAN.
>
> Good Luck,
>
> Dave V.
>
- Previous message: Thiago Conde Figueiro: "Re: Snort sensor placement"
- In reply to: Tom Lichti: "RE: Snort sensor placement"
- Next in thread: Dave Vehrs: "RE: Snort sensor placement"
- Next in thread: Lee Binette: "Re: Snort sensor placement"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|