Re: Multiple network segment monitor with Snort

From: Anton A. Chuvakin (anton_at_chuvakin.org)
Date: 09/25/03

  • Next message: Chris Reining: "Re: "False postive" database idea"
    Date: Thu, 25 Sep 2003 17:31:07 -0400 (EDT)
    To: Sergio Pozo Hidalgo <blitter_es@yahoo.es>
    
    

    >Can I use the same physical machine (with as many ethernet cards as
    >sensors I want to deploy) and use various and independent snort
    >processes? I neither know if only one Snort process can control
    Here is one way to do it for multiple VLANs or just multiple network
    cards (full HOWTO):

    http://www.securityfocus.com/infocus/1640
    http://www.securityfocus.com/infocus/1643

    Best,

    -- 
      Anton A. Chuvakin, Ph.D., GCI*
         http://www.chuvakin.org
       http://www.info-secure.org
    ---------------------------------------------------------------------------
    Captus Networks IPS 4000
    Intrusion Prevention and Traffic Shaping Technology to: 
     - Instantly Stop DoS/DDoS Attacks, Worms & Port Scans
     - Automatically Control P2P, IM and Spam Traffic
     - Precisely Define and Implement Network Security & Performance Policies
    FREE Vulnerability Assessment Toolkit - WhitePapers - Live Demo 
    http://www.securityfocus.com/sponsor/CaptusNetworks_focus-ids_000101
    ---------------------------------------------------------------------------
    

  • Next message: Chris Reining: "Re: "False postive" database idea"

    Relevant Pages

    • Re: Multiple network segment monitor with Snort
      ... > Can I use the same physical machine (with as many ethernet cards as ... > sensors I want to deploy) and use various and independent snort ... I run between 2-4 per FreeBSD-based sensor. ... - Precisely Define and Implement Network Security & Performance Policies ...
      (Focus-IDS)
    • Re: Need Help!!!: Simple Networking
      ... >> I've been trying to connect 2 WinXP PCs through Ethernet cards, ... I get no errors from the hardware, but I can't get the LAN ... it's possible to network two computers without a hub/router: ...
      (microsoft.public.windowsxp.network_web)
    • Re: Connecting two PCs in a mini-LAN
      ... > -I connected the two ethernet cards with a cable ... Heres your problem, the 192.30.x.x network is a routable network, what ... Also once you have changed the IP's to somethign private and ... an internal broken wire, see if you can get a hold of a cable tester to ...
      (alt.os.linux)
    • Re: Joining wireless and wired networks
      ... I've a computer at home I'm using for a network gateway, ... ethernet cards and a wireless card. ...
      (Fedora)
    • Re: SPT=137 DPT=137 ?????
      ... > If you mean the non-public IP Adresses - yes, ... Search for some ethernet cards which aren't in use and disable ... The queries are directed to public IPs. ... > this network interface. ...
      (comp.security.unix)