Results 1 to 7 of 7

Thread: SNORT & NAT Routing

  1. #1
    Junior Member
    Join Date
    Sep 2001
    Posts
    5

    Question SNORT & NAT Routing

    Anyone using a Linux box with Snort for IDS and also using a broadband gateway router, such as NetGear RT series?

    Would you place the IDS on the WAN side or the LAN side of the router?

    Just curious, I'm trying to find the best method of deployment.

    Cheers,

    Url

  2. #2
    Member
    Join Date
    Sep 2001
    Posts
    77
    Depends on your configuration....

    If you have a switched network, something like this....


    WAN --- Router --- Hub --- Switch --- Servers/Systems
    ...............................|
    ......................Snort System

    If you have a non-switched network, install it on your hub.


    Or, you can use it for firewalling and install it inline between the router and your hub/switch.

    cheers
    I\'m not a BOT I\'m a beer droid!
    Prepare to be Assimilated.

  3. #3
    Senior Member
    Join Date
    Sep 2001
    Posts
    412
    I would place it on the inside of your router, but i'd be careful, snort doesn't work on all switched networks - you need to make sure your switch can mirror traffic. Have look at snort.org for more info.

  4. #4
    Senior Member
    Join Date
    Aug 2001
    Posts
    170

    Arrow

    I know on at least the SMC barricades, there is the option of setting up an inside address as the DMZ (or default computer). That is, any traffic not expressly routed elsewhere will go to that computer (which is nice for an IDS).
    \"If you torture the data enough, it will confess.\" --Ronald Coase

  5. #5
    Junior Member
    Join Date
    Sep 2001
    Posts
    5
    Thank you all for the posts. I think I'm inclinded to go with the suggestion of using the DMZ, i.e., a single host that all traffic is routed through. This is where I'll put snort.

    Cheers,

    Url

  6. #6
    Junior Member
    Join Date
    Sep 2001
    Posts
    2
    Does Snort really work... What about Snort on a Windows box?

  7. #7
    Member
    Join Date
    Sep 2001
    Posts
    77
    Snort works very well, and is available for windows.

    cheers
    I\'m not a BOT I\'m a beer droid!
    Prepare to be Assimilated.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •