[Snort-users] snort behind firewall
PiersW at ...1865...
Thu Apr 26 07:23:37 EDT 2001
Of course if snort is on the firewall then in fact you get the choice:
monitoring attacks or intrusion (sucessfull attacks), based on which NIC you
monitor (internal vs external)...
From: chj at ...1888... [mailto:chj at ...1888...]
Sent: 26 April 2001 10:04
To: snort-users at lists.sourceforge.net
Subject: RE: [Snort-users] snort behind firewall
If the snort sensor is behind the firewall it is intrusion detection and if
the snort sensor is in front of (or on) the firewall it is attack detection
(from Stephen Nortcuts book Network Intrusion Detection)
More information about the Snort-users