Setting up an IDS

Networking/Security Forums -> Firewalls // Intrusion Detection - External Security

Author: Steelerfan21 PostPosted: Thu Apr 15, 2010 11:17 pm    Post subject: Setting up an IDS

I am using Snort as an IDS and trying to learn how to use it properly. I am currently just using it on my home network. Also, I have configured and tested it on my internal network successfully allowing me to log pings from other computers.

My question - How would I configure it on the other side of my firewall (router) to check incoming traffic instead of internal. I am not sure how I would be able to set it to my public ip.

Any insight or suggested readings are highly appreciated,

Author: eladl PostPosted: Sat Apr 17, 2010 3:08 pm    Post subject:
To listen the traffic on other interfaces, you can use port monitoring on your switch (or mirroring) so traffic from one port will show on another.

Also, you can use network taps to achieve that.

tell me more about the physical network connectivity in your configuration

Author: abrahamj PostPosted: Mon Sep 20, 2010 10:49 am    Post subject:
You can refer to this article,It introduce how to install and configure Ax3soft Sax2 in different network environments, including shared network and switched network, but it also applies to snort.[/url]

Networking/Security Forums -> Firewalls // Intrusion Detection - External Security

output generated using printer-friendly topic mod, All times are GMT + 2 Hours

Page 1 of 1

Powered by phpBB 2.0.x © 2001 phpBB Group