[Snort-sigs] Snort.conf Samples Project

Matt Jonkman matt at ...2436...
Thu Jun 16 13:30:05 EDT 2005


We're trying to put together a bunch of sample snort.conf config files
for different size and style installations. Particular emphasis on the
differences in preprocessor configs per different setups. That can get
very complicated, and deep documentation is sparse on many.

Please take a moment to look over:
http://www.bleedingsnort.com/staticpages/index.php?page=snortconf-samples

Specifically the one sample conf I put up to start the discussion that's
in the files link.

We'd love feedback on the preprocessor setup, and any other tips and
tricks you use and can share.

We intend to create at least the following configs:

Small  (home user style, dsl, cable, etc)
Medium  (Most installs. 20meg/sec traffic average, reasonable peaks)
Large   (High capacity, high traffic, lots of events)

Maybe even a snort_inline if there's much difference there. Any other
ideas welcome.

Please share what works for you and we'll get it all combined.

Thanks

Matt

--------------------------------------------
Matthew Jonkman, CISSP
Senior Security Engineer
Infotex
765-429-0398 Direct Anytime
765-448-6847 Office
866-679-5177 24x7 NOC
my.infotex.com
www.offsitefilter.com
www.bleedingsnort.com
--------------------------------------------


NOTICE: The information contained in this email is confidential
and intended solely for the intended recipient. Any use,
distribution, transmittal or retransmittal of information
contained in this email by persons who are not intended
recipients may be a violation of law and is strictly prohibited.
If you are not the intended recipient, please contact the sender
and delete all copies.
_______________________________________________
Bleeding-sigs mailing list
Bleeding-sigs at ...2727...
http://lists.bleedingsnort.com/mailman/listinfo/bleeding-sigs




More information about the Snort-sigs mailing list