![]() |
|
|
|||||||
| Petri.co.il is happy to award auglan the title of Most Valuable Member !!! |
| Register | Calendar |
Search |
Today's Posts |
Mark Forums Read |
| Notices |
|
|
IDS Implementationthis thread has 3 replies and has been viewed 1602 times
|
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||||||
|
||||||||
|
I would like to setup a snort box in my environment...what would be the best way to go about this?
I have read about using a SPAN port on a cisco switch, to have all traffic come through that 1 port that the IDS will monitor...which doesn't sound that great to me, or there is a network TAP which I believe is a separate piece of hardware you would have to buy. Does anyone have some good examples that have worked well? |
|
#2
|
|||||||||
|
|||||||||
|
Hi ekrengel
The way of configuring is: 1. Configure SPAN port mapped on another port connected to server\suspicious machine to check. 2. All traffic is captured by SNORT scanner and analysed (another Linux\Windows Based station with SNORT installed). 3. Frequent checks of status and mail\SMS notification on SNORT to real-time monitor issues. I think it's not the best way to forward all traffic throw SPAN port, especially in hard-working networks. The best way - to protect valuable information, but if You need complete defense no matter costs - its also possible. For me it works with IIS WEB-server and mirrored port for all incoming traffic from external users.
__________________
Regards Denis Laskov MCSA/E - CWNA - CCNA |
|
#3
|
|||||||||
|
|||||||||
|
Maybe this will be helpful:
http://www.cisco.com/warp/public/473/41.html
__________________
Regards Denis Laskov MCSA/E - CWNA - CCNA |
|
#4
|
|||||||||
|
|||||||||
|
ekrengel,
SPAN is great if you are on a budget however it has weakness that you should be aware. One of the biggest is that it doesn't scale well. The following link goes into detail on these weakness. Personally I use NetOptic TAPs. http://www.lovemytool.com/blog/2007/...orts-or-t.html Ryan |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| want to keep existing email ids on exchange while domain is changing | azaak | Exchange 2000 / 2003 | 6 | 22nd November 2007 19:58 |
| mapping between account names and security IDs | sobelman | Windows Server 2008 / 2008 R2 | 4 | 31st October 2007 20:42 |
| Windows 2003 Event IDs | aa11 | Windows Server 2000 / 2003 | 3 | 21st June 2007 11:17 |
| Implementation of RAID Level-5 | fkhan | Windows Server 2000 / 2003 | 4 | 7th June 2007 13:33 |
| Exchange 2000 implementation | roys | Exchange 2000 / 2003 | 1 | 8th July 2005 22:35 |