[Snort-users] Combination of snort and argus (or ntop)

Chowalit Tinnagonsutibout chowalit at ...7327...
Sat Oct 26 08:40:04 EDT 2002


Dear all.
    I just implement snort for my IDS system .. The sensor run on PIII 500
MHz , 256 M, 20 GB Hard-disk , RedHat 7.2 and 10 M Ethernet. The propose 
of IDS is
protect DMZ server.
    I use it to monitor traffic from spanning port of switch(Cisco 2950).
Normally, this  PC is quite good for snort sensor. But snort is
Signature-based NIDS, It does not prepare network traffic information
from DMZ for me. So I think I should find other network traffic
monitoring tool, argus (http://www.qosient.com/argus) and ntop are cool 
stuff.
Well, Some question in my mind was occured .... :-) ... Can I put 
argus(or ntop)
and snort into same (my sensor)PC ? Is it hard to implement? .. What is
the problem of this model?  One problem that I think... How the kernel
seperate process of sniffing on each sensor(argus(or ntop) and snort)?

Thank for Ur help

Chongg_fi





More information about the Snort-users mailing list