Snort on Gigabit [was Re: IDS\IPS that can handle one Gig]

From: mamo (mamo74_at_gmail.com)
Date: 05/29/05

  • Next message: Jonathan Glass: "Re: Value of IDS, ROI"
    Date: Sun, 29 May 2005 10:37:32 +0200
    To: "Byron L. Sonne" <blsonne@rogers.com>
    
    

    Hello Everybody.

    > On 5/21/05, Byron L. Sonne <blsonne@rogers.com> wrote:
    > It's not a vendor, but I've heard people have been running Snort quite
    > well on gig links.

    In this days I am trying to configure Snort to analyze traffic on a
    busy gigabit link (400-600Mbit), and I am finding I lose 60-80%
    traffic with the default snort config on freebsd (with device polling
    and some kernel tuning for sniffing purpose) with a quite good
    hardware. From my first analysis it looks like the problem is in how
    the prepocessor works and are configured (without preprocessor I can
    process near all the traffic)

    Is there anybody that used snort on gigabit connection that can share
    with us experience and tuning tips?

    Best Regards,
                     Mamo
    PS
    For sourcefire people or people that used their product.. What are the
    difference between the snort engine in the sourcefire appliance and
    the open source one?

    --------------------------------------------------------------------------
    Test Your IDS

    Is your IDS deployed correctly?
    Find out quickly and easily by testing it with real-world attacks from
    CORE IMPACT.
    Go to http://www.securityfocus.com/sponsor/CoreSecurity_focus-ids_040708
    to learn more.
    --------------------------------------------------------------------------


  • Next message: Jonathan Glass: "Re: Value of IDS, ROI"

    Relevant Pages

    • RE: [Snort-devel] RFC: Forking Snort
      ... I am very happy with Snort, it's sigs, plugins, etc.. ... The number of core developers on the Snort ... contributions to the codebase while not being insignificant are not what ... > wildly successfully open source project and Sourcefire (a growing, ...
      (Focus-IDS)
    • Re: IDS vs. IPS deployment feedback
      ... It is not accurate to state that the IPS ... Those two IPS technologies are NFR and Snort. ... signatures for the same vulnerability, ... Snort rules are developed by volunteers (or Sourcefire). ...
      (Focus-IDS)
    • Re: [Snort-devel] Re: RFC: Forking Snort
      ... > back out to the community at large. ... Combine that with my commitment to keeping Snort open source ... >>> own success. ... >>> successfully open source project and Sourcefire (a growing, ...
      (Focus-IDS)
    • Re: [Snort-devel] Re: RFC: Forking Snort
      ... back out to the community at large. ... Subject: [Snort-devel] Re: RFC: Forking Snort ... >>own success. ... >>successfully open source project and Sourcefire (a growing, ...
      (Focus-IDS)
    • Re: [Snort-users] RFC: Forking Snort
      ... I haven't been as good a communicator with the Snort community as ... order for Sourcefire to be successful, Snort has to be the best technology ... Sourcefire's CEOthat Snort must remain open source ...
      (Focus-IDS)