[Snort-users] snort behind firewall

Piers Williams PiersW at ...1865...
Thu Apr 26 07:23:37 EDT 2001

Of course if snort is on the firewall then in fact you get the choice:
monitoring attacks or intrusion (sucessfull attacks), based on which NIC you
monitor (internal vs external)...

-----Original Message-----
From: chj at ...1888... [mailto:chj at ...1888...]
Sent: 26 April 2001 10:04
To: snort-users at lists.sourceforge.net
Subject: RE: [Snort-users] snort behind firewall

If the snort sensor is behind the firewall it is intrusion detection and if
the snort sensor is in front of (or on) the firewall it is attack detection
(from Stephen Nortcuts book Network Intrusion Detection) 

More information about the Snort-users mailing list