[Snort-users] Combination of snort and argus (or ntop)
chowalit at ...7327...
Sat Oct 26 08:40:04 EDT 2002
I just implement snort for my IDS system .. The sensor run on PIII 500
MHz , 256 M, 20 GB Hard-disk , RedHat 7.2 and 10 M Ethernet. The propose
of IDS is
protect DMZ server.
I use it to monitor traffic from spanning port of switch(Cisco 2950).
Normally, this PC is quite good for snort sensor. But snort is
Signature-based NIDS, It does not prepare network traffic information
from DMZ for me. So I think I should find other network traffic
monitoring tool, argus (http://www.qosient.com/argus) and ntop are cool
Well, Some question in my mind was occured .... :-) ... Can I put
and snort into same (my sensor)PC ? Is it hard to implement? .. What is
the problem of this model? One problem that I think... How the kernel
seperate process of sniffing on each sensor(argus(or ntop) and snort)?
Thank for Ur help
More information about the Snort-users