Snort mailing list archives
Using SNORT for Internal IDS
From: "Pankaj Gupta" <pgupta () interloci com>
Date: Tue, 24 Jun 2003 16:16:50 -0400
I am not sure if Snort can be used to monitor internal attacks or intrusion activities. Also, can I use two copies of Snort (installed on two separate servers), one to monitor the external port outside my firewall and the other to monitor specific internal ports for signature matches. Does anyone have any experience, inputs or documentation on this matter? Thanks. Pankaj Gupta
Current thread:
- Using SNORT for Internal IDS Pankaj Gupta (Jun 25)
- Re: Using SNORT for Internal IDS Erek Adams (Jun 25)
- Re: Using SNORT for Internal IDS Bryan Irvine (Jun 25)
- <Possible follow-ups>
- RE: Using SNORT for Internal IDS Hutchinson, Andrew (Jun 25)
- Re: Using SNORT for Internal IDS Erek Adams (Jun 25)