Snort mailing list archives
RE: Preventing Attacks
From: "Slighter, Tim" <tslighter () itc nrcs usda gov>
Date: Wed, 26 Jun 2002 10:45:48 -0600
could you setup port mirroring on a connected switch at the first point of ingress past the firewall? -----Original Message----- From: Jeffrey Taylor [mailto:jeff () austinblues dyndns org] Sent: Wednesday, June 26, 2002 9:14 AM To: snort-users () lists sourceforge net Subject: Re: [Snort-users] Preventing Attacks Is it possible to have Snort listen inside the firewall? This is on a one host set up. I would like to see what is getting thru the firewall, not what is thrown at the firewall. TIA, Jeffrey Quoting McCammon, Keith <Keith.McCammon () eadvancemed com>:
Please specify you OS, as well as your sensor placement relative to the target host and any firewalls. It would also help to specify what type of help you seek. Do you want signature explanations? Do you want to know if your hosts were compromised? Do you want information on hardening your hosts? Do you want to know how to reconfigure your firewall so that Snort doesn't get so much of this crap fired across her bow?
------------------------------------------------------- This sf.net email is sponsored by: Jabber Inc. Don't miss the IM event of the season | Special offer for OSDN members! JabberConf 2002, Aug. 20-22, Keystone, CO http://www.jabberconf.com/osdn _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users ------------------------------------------------------- This sf.net email is sponsored by: Jabber Inc. Don't miss the IM event of the season | Special offer for OSDN members! JabberConf 2002, Aug. 20-22, Keystone, CO http://www.jabberconf.com/osdn _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- Preventing Attacks David Alexandre M. de Carvalho (Jun 25)
- <Possible follow-ups>
- RE: Preventing Attacks McCammon, Keith (Jun 26)
- Re: Preventing Attacks Jeffrey Taylor (Jun 26)
- Re: Preventing Attacks Jeff Taylor (Jun 27)
- Re: Preventing Attacks John Sage (Jun 28)
- Re: Preventing Attacks Jeffrey Taylor (Jun 26)
- Re: Preventing Attacks Jeffrey Taylor (Jun 27)
- RE: Preventing Attacks Hicks, John (Jun 26)
- RE: Preventing Attacks Slighter, Tim (Jun 26)