Security Basics mailing list archives

Fwd: Passive Snort Setup


From: Daniel Hood <dsmhood () gmail com>
Date: Fri, 20 Feb 2009 16:52:33 +1100

I think the Hogwash or snort_inline ideas look the best.

I want to manage it completely via BASE cause I am lazy and dont like
monitoring it any other way. If I used this same topology where would
I set up the webserver (which interface? and i know it would need an
ip) to run BASE? and would hogwash or snort_inline work? or would I
need a 3rd interface used for management?

Thanks,
Daniel


Current thread: