[Snort-users] Snort and Firewall on the same box
steve.shockley at ...1658...
Fri May 11 22:53:45 EDT 2001
> Sorry to dig up an old thread which I don't recall ever
> being satisfactorily resolved, but I've been pondering a good
> way to run snort and an FW on the same box and came up with
> this angle: Your box has three NICs: eth0, 1, and 2. Snort
That seems pretty complicated. I've used Snort on a machine running
ipf, and it seemed to work okay. If you're going to go to all that
trouble, why not just plug an internal machine with clipped transmit
pairs into the hub, and save the firewall's processor power?
More information about the Snort-users