[Snort-sigs] Snort.conf Samples Project

Matt Jonkman matt at ...2436...
Thu Jun 16 13:30:05 EDT 2005

We're trying to put together a bunch of sample snort.conf config files
for different size and style installations. Particular emphasis on the
differences in preprocessor configs per different setups. That can get
very complicated, and deep documentation is sparse on many.

Please take a moment to look over:

Specifically the one sample conf I put up to start the discussion that's
in the files link.

We'd love feedback on the preprocessor setup, and any other tips and
tricks you use and can share.

We intend to create at least the following configs:

Small  (home user style, dsl, cable, etc)
Medium  (Most installs. 20meg/sec traffic average, reasonable peaks)
Large   (High capacity, high traffic, lots of events)

Maybe even a snort_inline if there's much difference there. Any other
ideas welcome.

Please share what works for you and we'll get it all combined.



Matthew Jonkman, CISSP
Senior Security Engineer
765-429-0398 Direct Anytime
765-448-6847 Office
866-679-5177 24x7 NOC

NOTICE: The information contained in this email is confidential
and intended solely for the intended recipient. Any use,
distribution, transmittal or retransmittal of information
contained in this email by persons who are not intended
recipients may be a violation of law and is strictly prohibited.
If you are not the intended recipient, please contact the sender
and delete all copies.
Bleeding-sigs mailing list
Bleeding-sigs at ...2727...

More information about the Snort-sigs mailing list