re: Snort question

From: b. mac (aph3x@linuxmail.org)
Date: 09/29/01


Message-ID: <20010929005005.2941.qmail@linuxmail.org>
From: "b. mac" <aph3x@linuxmail.org>
To: SECURITY-BASICS@securityfocus.com
Date: Fri, 28 Sep 2001 20:50:05 -0400
Subject: re: Snort question

from the test i ran, yes it does... however, i think it depends on which machine snort is running and which machine the firewall software is running on.

my slack box is set up to masquerade my LAN as a firewall/gateway using netfilter. i installed snort on this same machine for the test. i then ssh'd to a remote shell account and tried to telnet back into my network, which netfilter DROP's by default. snort picked up all incoming TCP packets, as did netfilter.

if snort was running on a machine other than the firewall/gateway, such as an internal host, i dont believe it would pick up the packets, as they would never be routed to the internal host.

anyone have an idea as to what might happen if the packets were REJECT'd instead of DROP'd?

cheers

-- 

Get your free email from www.linuxmail.org

Powered by Outblaze



Relevant Pages

  • Re: [fw-wiz] Proxy and Stateful together ??
    ... > [on running snort on a bastion firewall] ... the two wildlly different handlings of packets --- ... snort, sniffing the raw stream, attempting some reassembly and URI ... that grade of gear for a T1, and had no firewall performance ...
    (Firewall-Wizards)
  • Re: Dynamic Firewall/IDS System
    ... > (firewall, IDS, etc.) and reacting appropriately could be a good thing. ... > I don't think this is a description of snort. ... the network guys from the colo -- that they get or got attacked. ... we deploy packet filter log rules that indicate the attack. ...
    (FreeBSD-Security)
  • Re: Snort as Firewall (WinXP)
    ... positives (Snort requires a lot of tuning to the network environment its ... other packets go by unchecked. ... My research is focused on writing a client-side firewall (which will be used ... > The Norwich University program offers unparalleled Infosec management ...
    (Security-Basics)
  • Re: Linux firewall/IDS/NAT suggestions
    ... > Should snort be running on the firewall machine or another machine? ... should I put the firewall and IDS box on a hub as the first ... other connected to a private net logging to a db that only has a private ... > a malicious attacker cannot hide rule changes? ...
    (Focus-Linux)
  • Re: IPFW & ICMP
    ... >>that the firewall should block the traffic first so as to prevent ... So then it is normal behaviour for snort to see the packets then get to ...
    (freebsd-questions)

Quantcast