Setting up and IDS (intrusion detection system) on ubuntu. Snort's documentation states to hook it up between the firewall and router with a switch. I'm wondering if a network tap would work just as well without wasting a switch. Thoughts?
Overclock.net › Forums › Software, Programming and Coding › Networking & Security › Snort IDS (Intrusion detection system) wiring
Featured Sponsors
Recent Reviews
-
I honestly love this cooler, but I think I'm gonna move on to another one soon, it just looks... A bit to bland compared to other flaming red (literally) coolers on the market.
-
Metro 2033 is one of the greatest FPS games ever made. Although not usually recognized as such, due to the horrible state the gaming industry is in, it succeeds largely on its storytelling,...
-
This is an update of the original Fractal Design Arc Midi. The solid left panel has been replaced by a panel with a plexiglass window and the top USB ports are now USB-3.0. Let me state at the...
-
I've used this headset extensively for MAG on PS3. The sounds were wonderful, the mic was crisp, and the ability to adjust peoples voice volume is absolutely invaluable. For $100 ( or less ) this...
-
The Pros The reason this card is one of the better non-Tahiti 7870s is because of Gigabyte's custom PCB. Gigabyte took the 7870 and replaced it's memory chips with Hynix memory so they perform a...
Snort IDS (Intrusion detection system) wiring
post #2 of 25
7/30/12 at 12:18am
- Ulquiorra
- 733mhz
-

- Joined: May 2008
- Location: rotherham
- Posts: 1,104
- Rep: 71 (Unique: 63)
- Reviews: 1
- Select All Posts By This User
Yup it would work fine
pretty much the same ^_^
pretty much the same ^_^
Supercomputer ^_^
(13 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| 1055T | M4A88T-D EVO USB3 | ATI 6850 | 4 GB |
| Optical Drive | OS | Monitor | Keyboard |
| DVD RW | Windows 8 Pro | lp1900 + 2 X 15 inch dell | Microsoft Comfort Curve |
| Power | Case | ||
| 600watt thermaltake | antec 200 | ||
| View all | |||
Supercomputer ^_^
(13 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| 1055T | M4A88T-D EVO USB3 | ATI 6850 | 4 GB |
| Optical Drive | OS | Monitor | Keyboard |
| DVD RW | Windows 8 Pro | lp1900 + 2 X 15 inch dell | Microsoft Comfort Curve |
| Power | Case | ||
| 600watt thermaltake | antec 200 | ||
| View all | |||
- swat565
- Networking Nut
-

- Joined: Sep 2009
- Location: Anchorage, Alaska
- Posts: 780
- Rep: 50 (Unique: 42)
- Trader Rating: 2
- Select All Posts By This User
post #4 of 25
7/30/12 at 2:12pm
- Ulquiorra
- 733mhz
-

- Joined: May 2008
- Location: rotherham
- Posts: 1,104
- Rep: 71 (Unique: 63)
- Reviews: 1
- Select All Posts By This User
When you say you need it to monitor 2 nics, are you putting it as a tap interface (a device stiing in promiscus mode with one nic) or as inbetween 2 things?
I thought you mean the first but the second post made me think you were taking about the second (sorry its my fault ^_^)
As for the setup it should be the same as it would just look at info teravering the bridge (i think) but i will check at work tommorow to look at our internal documentation
I thought you mean the first but the second post made me think you were taking about the second (sorry its my fault ^_^)
As for the setup it should be the same as it would just look at info teravering the bridge (i think) but i will check at work tommorow to look at our internal documentation
Supercomputer ^_^
(13 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| 1055T | M4A88T-D EVO USB3 | ATI 6850 | 4 GB |
| Optical Drive | OS | Monitor | Keyboard |
| DVD RW | Windows 8 Pro | lp1900 + 2 X 15 inch dell | Microsoft Comfort Curve |
| Power | Case | ||
| 600watt thermaltake | antec 200 | ||
| View all | |||
Supercomputer ^_^
(13 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| 1055T | M4A88T-D EVO USB3 | ATI 6850 | 4 GB |
| Optical Drive | OS | Monitor | Keyboard |
| DVD RW | Windows 8 Pro | lp1900 + 2 X 15 inch dell | Microsoft Comfort Curve |
| Power | Case | ||
| 600watt thermaltake | antec 200 | ||
| View all | |||
- swat565
- Networking Nut
-

- Joined: Sep 2009
- Location: Anchorage, Alaska
- Posts: 780
- Rep: 50 (Unique: 42)
- Trader Rating: 2
- Select All Posts By This User
Quote:
Originally Posted by Ulquiorra 
When you say you need it to monitor 2 nics, are you putting it as a tap interface (a device stiing in promiscus mode with one nic) or as inbetween 2 things?
I thought you mean the first but the second post made me think you were taking about the second (sorry its my fault ^_^)
As for the setup it should be the same as it would just look at info teravering the bridge (i think) but i will check at work tommorow to look at our internal documentation

When you say you need it to monitor 2 nics, are you putting it as a tap interface (a device stiing in promiscus mode with one nic) or as inbetween 2 things?
I thought you mean the first but the second post made me think you were taking about the second (sorry its my fault ^_^)
As for the setup it should be the same as it would just look at info teravering the bridge (i think) but i will check at work tommorow to look at our internal documentation
Maybe I'm going about it the wrong way then. I was planning on putting a tap in between my PIX 501 and switch for Snort rig to sniff the packets.
post #6 of 25
7/30/12 at 2:45pm
- Ulquiorra
- 733mhz
-

- Joined: May 2008
- Location: rotherham
- Posts: 1,104
- Rep: 71 (Unique: 63)
- Reviews: 1
- Select All Posts By This User
They way your descirbing it i think tis just the standard way
Internet -> snort -> lan
Snort acts a bridge which just passes traffic though
Internet -> snort -> lan
Snort acts a bridge which just passes traffic though

Supercomputer ^_^
(13 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| 1055T | M4A88T-D EVO USB3 | ATI 6850 | 4 GB |
| Optical Drive | OS | Monitor | Keyboard |
| DVD RW | Windows 8 Pro | lp1900 + 2 X 15 inch dell | Microsoft Comfort Curve |
| Power | Case | ||
| 600watt thermaltake | antec 200 | ||
| View all | |||
Supercomputer ^_^
(13 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| 1055T | M4A88T-D EVO USB3 | ATI 6850 | 4 GB |
| Optical Drive | OS | Monitor | Keyboard |
| DVD RW | Windows 8 Pro | lp1900 + 2 X 15 inch dell | Microsoft Comfort Curve |
| Power | Case | ||
| 600watt thermaltake | antec 200 | ||
| View all | |||
- swat565
- Networking Nut
-

- Joined: Sep 2009
- Location: Anchorage, Alaska
- Posts: 780
- Rep: 50 (Unique: 42)
- Trader Rating: 2
- Select All Posts By This User
Quote:
Yeah It has to pass data100% untouched though, I have my setup
phoneline-->Modem--->PIX-501
I have the modem in a complete pass-through mode letting my PIX501 do PPPOE authentication. My concern is changing the setup when the snort rig is actually physically in-between the modem and PIX would be a good idea and it might mess up the PPPOE pass-through.
post #8 of 25
7/31/12 at 3:05am
- Ulquiorra
- 733mhz
-

- Joined: May 2008
- Location: rotherham
- Posts: 1,104
- Rep: 71 (Unique: 63)
- Reviews: 1
- Select All Posts By This User
Hmm had a quick look and it should work, you justforward everything accrossm, you could do a test by prepering the box and dropping it in xD
Supercomputer ^_^
(13 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| 1055T | M4A88T-D EVO USB3 | ATI 6850 | 4 GB |
| Optical Drive | OS | Monitor | Keyboard |
| DVD RW | Windows 8 Pro | lp1900 + 2 X 15 inch dell | Microsoft Comfort Curve |
| Power | Case | ||
| 600watt thermaltake | antec 200 | ||
| View all | |||
Supercomputer ^_^
(13 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| 1055T | M4A88T-D EVO USB3 | ATI 6850 | 4 GB |
| Optical Drive | OS | Monitor | Keyboard |
| DVD RW | Windows 8 Pro | lp1900 + 2 X 15 inch dell | Microsoft Comfort Curve |
| Power | Case | ||
| 600watt thermaltake | antec 200 | ||
| View all | |||
post #9 of 25
8/2/12 at 12:23am
- Killbuzzjrad
- Networking Nut
- Joined: Jul 2012
- Posts: 136
- Rep: 17 (Unique: 17)
- Select All Posts By This User
You can use a cheap hub.
Super Trooper
(12 items) |
ESXi Whitebox
(10 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| i7 - 3930K | Asus Rampage IV Formula | MSI GTX 680 Lightning | G.Skill RipjawZ |
| Hard Drive | OS | Monitor | Keyboard |
| Crucial M4 | Windows 7 Professional | 2x ASUS 27" LCD | Razer Black Widow Ultimate |
| Power | Case | Mouse | Audio |
| Corsair HX850 | Cooler Master Storm Trooper | Cooler Master Storm Recon | Logitech G35 |
| View all | |||
| CPU | Motherboard | RAM | Hard Drive |
|---|---|---|---|
| Xeon 1245 v2 | GIGABYTE GA-H77N-WIFI | Patriot Viper 3 16GB PV316G160C0K | Seagate Barracude 7200RPM |
| Hard Drive | Hard Drive | Cooling | OS |
| Seagate Barracuda 7200RPM | Samsung 840 SSD | Stock | ESXi 5.1 |
| Power | Case | ||
| PC Power and Cooling Silencer MK III 400W | Fractal Designs Node 304 | ||
| View all | |||
Super Trooper
(12 items) |
ESXi Whitebox
(10 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| i7 - 3930K | Asus Rampage IV Formula | MSI GTX 680 Lightning | G.Skill RipjawZ |
| Hard Drive | OS | Monitor | Keyboard |
| Crucial M4 | Windows 7 Professional | 2x ASUS 27" LCD | Razer Black Widow Ultimate |
| Power | Case | Mouse | Audio |
| Corsair HX850 | Cooler Master Storm Trooper | Cooler Master Storm Recon | Logitech G35 |
| View all | |||
| CPU | Motherboard | RAM | Hard Drive |
|---|---|---|---|
| Xeon 1245 v2 | GIGABYTE GA-H77N-WIFI | Patriot Viper 3 16GB PV316G160C0K | Seagate Barracude 7200RPM |
| Hard Drive | Hard Drive | Cooling | OS |
| Seagate Barracuda 7200RPM | Samsung 840 SSD | Stock | ESXi 5.1 |
| Power | Case | ||
| PC Power and Cooling Silencer MK III 400W | Fractal Designs Node 304 | ||
| View all | |||
post #10 of 25
8/2/12 at 1:52am
- Ulquiorra
- 733mhz
-

- Joined: May 2008
- Location: rotherham
- Posts: 1,104
- Rep: 71 (Unique: 63)
- Reviews: 1
- Select All Posts By This User
It would but you would have to crimp a cable so the box would be able to Rx but not Tx as you dont want people to know snort is there 

Supercomputer ^_^
(13 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| 1055T | M4A88T-D EVO USB3 | ATI 6850 | 4 GB |
| Optical Drive | OS | Monitor | Keyboard |
| DVD RW | Windows 8 Pro | lp1900 + 2 X 15 inch dell | Microsoft Comfort Curve |
| Power | Case | ||
| 600watt thermaltake | antec 200 | ||
| View all | |||
Supercomputer ^_^
(13 items) |
| CPU | Motherboard | Graphics | RAM |
|---|---|---|---|
| 1055T | M4A88T-D EVO USB3 | ATI 6850 | 4 GB |
| Optical Drive | OS | Monitor | Keyboard |
| DVD RW | Windows 8 Pro | lp1900 + 2 X 15 inch dell | Microsoft Comfort Curve |
| Power | Case | ||
| 600watt thermaltake | antec 200 | ||
| View all | |||
Return Home
Back to Forum: Networking & Security
- Snort IDS (Intrusion detection system) wiring
Overclock.net › Forums › Software, Programming and Coding › Networking & Security › Snort IDS (Intrusion detection system) wiring
Currently, there are 1547 Active Users
(409 Members and 1138 Guests)
Recent Discussions
- › [VC] First GeForce GTX 780 Review Leaks Out, Inno3D GTX 780 iChill... 9 seconds ago
- › [DS] Mortal Kombat PC Announced! 23 seconds ago
- › [Case Mod] MurderMac 1 minute ago
- › [Hermitage Akihabara] Gigabyte Japan announces motherboard models 1 minute ago
- › A10 5800k for a budget PC? 2 minutes ago
- › [Build Log] An old man's first blinged out water build. 2 minutes ago
- › [RP] Alleged New Android 4.3 Features Leaked By HTC Ahead Of Google... 3 minutes ago
- › [The Inquierer] GIF creator sparks outrage by revealing that it's... 4 minutes ago
- › Need info on SSD and HDD please 4 minutes ago
- › [Official] Delidded Club 5 minutes ago
View: New Posts | All Discussions
Recent Reviews
- › Cooler Master Hyper 212 EVO CPU Cooler (RR-212E-20PK-R1) by junhawng
- › Metro: Last Light - Standard Edition by boredgunner
- › Fractal Design Arc Midi R2 FD-CA-ARC-R2-BL-W Computer Case With... by Alan G
- › Wireless Stereo Headset by DoomDash
- › GIGABYTE Radeon HD 7870 GHz Edition GV-R787OC-2GD Video Card by VitalShot
- › Crucial Ballistix sport 16GB (2 x 8GB) 240-Pin DDR3 SDRAM DDR3 1600... by Fieldsweeper
- › Creative 70SB150000000 Sound Card by Fieldsweeper
- › ASUS PB Series PB278Q 27"" 5ms (GTG) WQHD Widescreen LED... by R3apR369
- › SilverStone Aluminum Body ATX Full Tower Computer Case TJ07B -... by R3apR369
- › Cooler Master HAF 922 RC-922M-KKN1-GP Black Steel + Plastic and... by Steve1300
View: More Reviews
New Articles
- › Rackmount Storage Devices for your mypccase by chriseddins
- › Online free image resizer by morgan0021
- › Maid Service Stroud by jacob5564
- › METRO 2033 STARTUP CRASH FIX WORKS by xiangelo
- › Why are DNS Servers Important? How to make... by exzacklyright
- › Titanium Backup Guide For Newbies by exzacklyright
- › How to install ADB (Android Debug Bridge) by exzacklyright
- › How to take ownership of a file, folder, or... by exzacklyright
- › How to disable the open file security warning... by exzacklyright
- › Clean and Make a USB Bootable Flash Drive for... by exzacklyright
View: New Articles | All Articles
Home | Reviews | Forums | Articles | My Profile
About Overclock.net | Join the Community | Advertise | Contact Us | All Staff
© 2013 Shogun Interactive Development Overclock.net is powered by Huddler Tech | FAQ | Support | Privacy | ToS | DMCA | Site Map
About Overclock.net | Join the Community | Advertise | Contact Us | All Staff
© 2013 Shogun Interactive Development Overclock.net is powered by Huddler Tech | FAQ | Support | Privacy | ToS | DMCA | Site Map




