Re: Snort / acidlab and mysql

2003-11-04 Thread Marcelo Mendes Genaro
I think that is most secure use a external box to archive IDS data and reports. The firewall boxes normally generate a lot of megabytes of log and are very critical parts of network, so I think that the best way to avoid crashes and possible security issues. It' possible create a vlan for this

Re: Snort / acidlab and mysql

2003-11-04 Thread Marcelo Mendes Genaro
I think that is most secure use a external box to archive IDS data and reports. The firewall boxes normally generate a lot of megabytes of log and are very critical parts of network, so I think that the best way to avoid crashes and possible security issues. It' possible create a vlan for this

Snort / acidlab and mysql

2003-11-03 Thread Craig
Hi guys Is it a perferrable to have snort and acidlab running on a firewall machine masquerding a network and logging to an internal server running apache-ssl and mysql ? I would like to setup some sort of IDS but also have more info on traffic in the internal network ? Thnaks ..Craig -- To

Snort / acidlab and mysql

2003-11-03 Thread Craig
Hi guys Is it a perferrable to have snort and acidlab running on a firewall machine masquerding a network and logging to an internal server running apache-ssl and mysql ? I would like to setup some sort of IDS but also have more info on traffic in the internal network ? Thnaks ..Craig