[Snort-sigs] SNORT help

Frank Knobbe frank at ...1978...
Thu Mar 9 17:34:07 EST 2006

On Thu, 2006-03-09 at 20:15 -0500, FRANK SORNATALE wrote:
> Is there anyone out there that understands snort real well that can help 
> walk me through each problem.  I know they are really basic for you guys, 
> but I never delt with snort and the manual isn't helping me much.  Maybe 
> through AIM i could get some help.

If you never used Snort and don't know the rule language and how to
configure Snort, and you have been given the task to configure it in
some network (maybe your own, maybe a client), then I suggest you
contract with a consultant that has used Snort before.

Not just is the "get free consulting via mail list or IRC" frowned upon,
it probably will do more harm than good. Snort needs to be properly
configured and tuned to your network, and that is hard to do remotely.
You really want to have someone spend some time with you to understand
not just your needs, but also your network, and then have Snort custom
configured to your network.

Snort is not a one-size-fits-all product. It takes time to get it set up
properly for your network. You really want the help of a consultant that
can sit down with you and work on that.


It is said that the Internet is a public utility. As such, it is best
compared to a sewer. A big, fat pipe with a bunch of crap sloshing
against your ports.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20060309/b095e0f6/attachment.sig>

More information about the Snort-sigs mailing list