Re: Anyone used SNORT [7:4436]

2001-05-16 Thread Keith Woodworth
On Tue, 15 May 2001, Brad McConnell wrote: |+I do a semi-classical arrangement. We have two pipes to the net going to |+two different switches. I use SPAN to send all ingress traffic on the |+external router to a port which I plug into a hub. I then do the same on |+the second pipe, and plug

Re: Anyone used SNORT [7:4436]

2001-05-16 Thread Brad McConnell
I really don't see any reason why this wouldn't work. If it's a single pipe, that'll do, if there's more than one 7206 on your end, you'll need two nics with snort active on both, or a hub'd setup. Unless you're looking at over 40Mb/s sustained, I really don't like running snort on two

Anyone used SNORT [7:4436]

2001-05-14 Thread Roberts, Timothy
Has anyone used SNORT for IDS purposes? Any reviews? Confidentiality Notice: This e-mail message, including any attachments, is for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorized review, use, disclosure or distribution is

Re: Anyone used SNORT [7:4436]

2001-05-14 Thread simonis
Roberts, Timothy wrote: Has anyone used SNORT for IDS purposes? Any reviews? You'll find a whole lot of SNORT users on the SNORT mailing list. Just don't go asking them Cisco questions... Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=4445t=4436

Re: Anyone used SNORT [7:4436]

2001-05-14 Thread Brad McConnell
I do a semi-classical arrangement. We have two pipes to the net going to two different switches. I use SPAN to send all ingress traffic on the external router to a port which I plug into a hub. I then do the same on the second pipe, and plug the IDS box running snort into the hub (thus, all