Snort mailing list archives

Re: inside or outside


From: Erek Adams <erek () theadamsfamily net>
Date: Fri, 19 Jul 2002 16:32:46 -0700 (PDT)

On 19 Jul 2002, Frank Knobbe wrote:

it depends how you want to use Snort. If you want to use it as an
Intrusion Detection Systems, it should be placed inside the firewall to
alert you for for anything weird that slipped through your firewall
(such as... uhm... an intrusion :)

Oh, like those ever happen.  Those 'intrusions' are just made up to make us
forget about the Illuminati.  ;-)

Seriously, Seth...  :)  There are pros and cons to placing it (a sensor) in
either location.  You might want to have a look at this email thread I snipped
from another list that has some good statements about placement:

        http://www.theadamsfamily.net/~erek/snort/ids_placement.txt

Hope that helps.

-----
Erek Adams
Nifty-Type-Guy
TheAdamsFamily.Net



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: