[Snort-users] Basic questions about snort

Jason Lewis jlewis at ...1831...
Sat Apr 14 20:51:19 EDT 2001


First, if there is a FAQ that covers my questions could someone point me to
it?  I haven't been able to find one.

Has anyone deployed snort in an enterprise class network?  If so, where did
you go to help you get things working?  I am looking to roll snort out and I
don't want to reinvent the wheel.  If there isn't one, I will document my
experience.

Does snort get along with ipchains?  If I run snort on the same interface
that I am running ipchains rules on, will it be able to detect attacks?  I
guess the real question is, do the ipchains rules run before snort has a
chance to see them?

Jason





More information about the Snort-users mailing list