Snort mailing list archives

Snort + Microsoft ISA


From: "Michael Miller" <michael.miller () state co us>
Date: Tue, 8 Nov 2005 09:06:23 -0700

We've got an ISA server that's protecting our internal network from a
VLAN used for kiosk and WiFi access. I'd like to sniff that traffic and
funnel it through snort, but since the routing occurs within ISA server,
I'm not entirely sure if I can do this on-box. It seems like something
like WinPCAP has the potential to muck-up ISA operations. As this is a
production box, I'd like to use a little care before wading in and
installing WinPCAP+snort.

Has anyone used snort on an ISA box?

I suppose I could hang another NIC off our IDS box and portspan that
vlan to it, but the ISA box spends most of its life idle anyway.


-------------------------------------------------------
SF.Net email is sponsored by:
Tame your development challenges with Apache's Geronimo App Server. Download
it for free - -and be entered to win a 42" plasma tv or your very own
Sony(tm)PSP.  Click here to play: http://sourceforge.net/geronimo.php
_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: