locking down snort
From: blaqb0x (blaqb0x_at_netscape.net)
Date: 06/24/04
- Next message: Gerard Wassink: "Re: newbie security question"
- Previous message: h2server: "newbie security question"
- Next in thread: tutaepaki: "Re: locking down snort"
- Reply: tutaepaki: "Re: locking down snort"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: 24 Jun 2004 13:34:15 -0700
Hi,
I have some machines running snort. I'd like to restrict ssh/http
and other access to them. However, I'm not sure if in doing so, would
snort not 'grab' and analyze traffic hitting those ports. I guess I'm
asking
- if I blocked those ports from the outside world with IPTBLES would I
still detect say a port scan on those ports?
- Who captures the packets first: Firewall(IPTABLES) or SNORT?
Thanks,
- Next message: Gerard Wassink: "Re: newbie security question"
- Previous message: h2server: "newbie security question"
- Next in thread: tutaepaki: "Re: locking down snort"
- Reply: tutaepaki: "Re: locking down snort"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|