|
|||||||||||
|
RE: snort-inline inbound ruleset?
From: Gonzalez, Albert <albert.gonzalez(at)eds.com>
Date: Mon Feb 03 2003 - 13:38:17 EST
Take in mind, both of these use Snort as the 'detection' engine. But they are geared towards the 'prevention' of attacks. Though snort can be compiled with flexresp and have the ability to send rst, icmp_port_unreachable and others. Hogwash does the dropping for you, while SnortSam can pass it off to firewalls(supports various). Snort-inline uses iptables. I hope that helps in some faint way :-) Cheers! Alberto Gonzalez
SnortSam - http://www.snortsam.net
-----Original Message-----
Hi all,
I'm fairly new to the IDS scene. I want to deploy some sort of open
source IPS. I've read most of the stuff from the honeynet project and
those guys are doing a great job with snort-inline. They have a great
default ruleset to filter outgoing traffic. I was wondering if
snort-inline is a recommended approach for an IPS at this point and if
so, does someone have a good default blocking ruleset for incoming
untrusted traffic they could point me to? I have been having a huge
problem with false positive rates with snort on my network and i'm
struggling to come up with an IPS solution that won't block legitimate
traffic. Would people recommend I use hogwash or something else instead
of snort-inline?
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:08 EDT |
||||||||||
|
|||||||||||