An excellent place to start would be : http://www.snort.org/documentation.html
And while you are there, pick up snort also. :) Bye Dirk Cornelis, Security Officer * E-Mail: [EMAIL PROTECTED] General Services & Investments * Tel: +32 (02) 600 64 00 Information Systems * Fax: +32 (02) 600 64 01 Berkenlaan 7 * Web: http://www.deloitte.be B-1831 Diegem - Belgium -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: maandag 29 oktober 2001 10:01 To: [EMAIL PROTECTED] Subject: IDS White Papers/Documents Hi all, Any help with the following greatly appreciated! Can anyone point me in the right direction for good white papers/documents on deciding where to locate an IDS on a network? The background to this is that I want to implement an IDS on a network which has an incoming/outgoing Internet connection for all users. There is currently a firewall protecting this connection, but I want to know whether I should locate the IDS in front of or behind the firewall? Should the IDS be placed in a DMZ or not? (As you can tell, I am new to all this!) Regards, Mark. _______________________________________________________________________ Never pay another Internet phone bill! Freeserve AnyTime, for all the Internet access you want, day and night, only £12.99 per month. Sign-up at http://www.freeserve.com/time/anytime "E-mail disclaimer:This e-mail, and any attachments thereto, is intended only for use by the addressee(s) named herein and may contain legally privileged and/or confidential information. If you are not the intended recipient, please note that any review, dissemination, disclosure, alteration, printing, copying or transmission of this e-mail and/or any file transmitted with it, is strictly prohibited and may be unlawful. If you have received this e-mail by mistake, please immediately notify the sender and permanently delete the original as well as any copy of any e-mail and any printout thereof."