|
|||||||||||
|
RE: IDS using Taps & network bridging
From: Benninghoff, John <John.Benninghoff(at)Rbcdain.com>
Date: Tue Nov 26 2002 - 15:36:56 EST
Also, I agree with others that Linux isn't necessarily the best platform for doing this sort of thing. OpenBSD would work quite well. I notice you didn't specifically mention inline snort ... have you looked at this ? (http://www.snort.org/dl/contrib/patches/inline/)
-----Original Message-----
Hi, I'm doing some testing to see how Taps could be implimented in my environment. I've read some information from Snort.org and other sources showing the use of taps in conjunction with a switch. I would like to eliminate the switch for the aggregation and I'm looking for ideas on how to do that. The IDS platform is snort running on Intel with Linux 2.4 Kernel. Ideas I've had so far are:
I'm open to any suggestions but I'm really interested in the network bridging.
What I've done so far is:
I see mostly massive amounts of ARP traffic - any help on this would be appreciated. Regards, Jim "Life's tough - but it's a whole lot tougher when your stupid!" Received on Tue Nov 26 19:46:51 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:04 EDT |
||||||||||
|
|||||||||||