Re: Snoop on Cisco IDS (Was: CISCO IDS Packet capture)

From: Jason Haar (Jason.Haar_at_trimble.co.nz)
Date: 04/15/04

  • Next message: Anton A. Chuvakin: "Re: Sourcefire IDS?"
    Date: Fri, 16 Apr 2004 07:05:03 +1200
    To: focus-ids@securityfocus.com
    
    

    On Thu, Apr 08, 2004 at 03:11:20PM -0400, Alex Arndt wrote:
    > The new version (v4.0 or newer) runs on top of Red Hat Linux, so
    > it would use tcpdump instead of snoop. Unfortunately, just as Chad
    > Skipper pointed out in another reply, you can't run the IDS software
    > and tcpdump at the same time (unlike snoop and IDS in v3.1 and older)

    Does anyone know why that is?

    I routinely run tcpdump, snort and ethereal simultaneously on the same
    interface under Linux. The pcap stuff takes care of any issues, so what's so
    different about Cisco's "Linux"?

    -- 
    Cheers
    Jason Haar
    Information Security Manager, Trimble Navigation Ltd.
    Phone: +64 3 9635 377 Fax: +64 3 9635 417
    PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Anton A. Chuvakin: "Re: Sourcefire IDS?"

    Relevant Pages

    • Re: Setting Up NTP for Time Sync
      ... the XP boot and the ntp restart didn't change a thing. ... >> didn't sync its time with XP. ... > Use ntpdate to coarse sync the Linux box before ... use Ethereal instead of tcpdump. ...
      (comp.os.linux.networking)
    • Re: Cant get port forwarding to work (LinkSys)
      ... > linux box to see what if anything is coming through the linksys. ... Checked the router log, good suggestion. ... for the desired port, good tip. ... I'm having trouble with tcpdump and ehthereal (ethereal ...
      (comp.security.firewalls)
    • Re: non-blocking socket close
      ... Well, since the receiving side is also Linux, then tcpdump will show ... that the FIN is sent, and the data you are expecting is not sent. ... I'm just talking about delivery of the data before FIN. ...
      (comp.unix.programmer)
    • ethernet if goes down?
      ... I just migrated my home server from linux to FreeBSD 4.10. ... But the modem LAN light flashes. ... show up in tcpdump ...
      (comp.unix.bsd.freebsd.misc)
    • Re: sniffer in redhat 9
      ... Under Linux: ... You must be root or tcpdump must be installed setuid to root ... Or he can install it from the CD.... ...
      (RedHat)