[Snort-users] Asymmetric Data

Michael L. Artz dragon at ...8731...
Fri Jul 18 11:08:02 EDT 2003


How well does snort handle asymmetric data, i.e. an incoming link but no 
outgoing link?  I figure that most of the signatures should be fine, 
since most of them are looking for content and/or packet flags, but what 
about the preprocessors, such as stream4?  Are there certain 
preprocessors that should be left turned off if snort is only seeing one 
side of the traffic?  Any suggestions on how to best tune snort given 
only one side of a link?

I understand that it is best to get both sides together, but that is not 
a possibility in this case.  From talking to other network admins, I 
understand that this is also not as uncommon as it would seem, 
especially dealing with high speed links.

-Mike





More information about the Snort-users mailing list