RE: high-speed NIDS (>1.7GBit/sec traffic) required.

From: McCammon, Keith (Keith.McCammon@eadvancemed.com)
Date: 07/15/02


Date: Mon, 15 Jul 2002 13:05:32 -0400
From: "McCammon, Keith" <Keith.McCammon@eadvancemed.com>
To: "s s" <solananexus@yahoo.com>, <focus-ids@securityfocus.com>


> I would like to go with snort.

OK.

> what kind of hardware would be required to handle
> this?

Depends...

How many rules are you planning to run?
How much RAM does Snort have available?
What benchmarking have you performed, and what's choking?
What other services (if any) will run on the box?
What do your command-line arguments look like?
What type of output plugins are active?
 
> I have tried a Sun 280R, no avail. Dropping around
> 70-80k packets per second, too much for the box.

That's believable, but it's difficult to advise based on this information. Please elaborate.

Cheers

Keith



Relevant Pages

  • Re: [Full-disclosure] Suggestion for IDS
    ... > about snort as NIDS, but, that's software based. ... > hardware based that will work transparently with our Cisco PIX, ... video surveillance camera protects anything. ...
    (Full-Disclosure)
  • Re: [SLE] suse 9.2 snort
    ... >is that hardware enough for snort? ... Please note - Due to the intense volume of spam, we have installed site-wide spam ...
    (SuSE)
  • Re: Help, my machine has been hacked
    ... >>> of the hardware box and filter invalid packets, ... I've built and installed snort. ... use use the 192.168.0.0 net as it's home net but I otherwise left it the ...
    (comp.os.linux.security)
  • RE: high-speed NIDS (>1.7GBit/sec traffic) required.
    ... You could also look at IDS load balancing using the Toplayer switch, ... more inexpensive hardware. ... copy at www.digitz.org or the ISS website. ... > I would like to go with snort. ...
    (Focus-IDS)
  • [Full-disclosure] Suggestion for IDS
    ... Our company plan to install IDS to protect our resources, ... about snort as NIDS, but, that's software based. ... hardware based that will work transparently with our Cisco PIX, ...
    (Full-Disclosure)

Loading