Re: using linux for security at work??

From:
Date: 10/23/02


Date: Wed, 23 Oct 2002 08:38:01 -0500

On Wed, 23 Oct 2002 06:50:34 -0500, lee wrote:

> 2 we are having a few weird things going on at the moment with
> something accessing the internet from the LAN and were thinking of
> putting a sniffer next to the firewall to see whats going on. any
> suggestions for software for sniffing and scanning the LAN would be
> good. Again free and pay for
>
You might want to install a copy of ntop (http://www.ntop.org/ntop.html)
to get an overall view of the network activity and then use tcpdump or
ethereal to examine specific connections.

> 3 We have an IDS box on the net already, its unix on a sun something
> or other. Its managed by the US side of the company. We would like
> something of our own for the LAN and Internet, I know of snort, is this
> any good or what other options are there? I have been told that the US
> side are thinking of changing these boxes for snort which is what makes
> me think is good.
>
snort is very, very good as an IDS.

-- 
The instructions said to use Windows 98 or better, so I installed RedHat.



Relevant Pages

  • update to using linux for security at work??
    ... What I will ask is if I run snort on the internal side of our firewall what ... >> and I would like to try out some others on linux. ... >> any suggestions for software for sniffing and scanning the LAN would be ... >> our own for the LAN and Internet, I know of snort, is this any good or ...
    (comp.os.linux.security)
  • Re: =?ISO-8859-15?Q?Ben=FCtzer_von_Webradio_ausfindig_ma?= =?ISO-8859-15?Q?chen=2E?=
    ... kommt halt ne alte Kiste mit Snort oder Astaro mit IDS druff. ... Wir haben hier die Astaro, die ein Snort integriert hat und dort wird halt alles gescannt was aus dem Internet kommt, und was In das Internet geht. ...
    (de.comp.security.firewall)
  • Re: =?ISO-8859-15?Q?Ben=FCtzer_von_Webradio_ausfindig_ma?= =?ISO-8859-15?Q?chen=2E?=
    ... kommt halt ne alte Kiste mit Snort oder Astaro mit IDS druff. ... Wir haben hier die Astaro, die ein Snort integriert hat und dort wird halt alles gescannt was aus dem Internet kommt, und was In das Internet geht. ...
    (de.comp.security.firewall)
  • Re: Moving Exchange Server
    ... Placing them in the LAN gives internal users 100% access with no firewall to ... DMZ, thus 0% risk/ports open between them. ... If Microsoft Exchange and/or Active Directory cannot run ... >> Internet is better? ...
    (microsoft.public.exchange.setup)
  • RE: Firewall Rule Set not allowing access to DNS servers?
    ... > My LAN is configured with static IP addresses, ... > I have full connectivity with the internet from every machine on my ... > # Allow out access to my ISP's Domain name server. ... > # Interrogate packets originating from the public internet ...
    (freebsd-questions)

Loading