[Snort-users] Asymmetric Data
Michael L. Artz
dragon at ...8731...
Fri Jul 18 11:08:02 EDT 2003
How well does snort handle asymmetric data, i.e. an incoming link but no
outgoing link? I figure that most of the signatures should be fine,
since most of them are looking for content and/or packet flags, but what
about the preprocessors, such as stream4? Are there certain
preprocessors that should be left turned off if snort is only seeing one
side of the traffic? Any suggestions on how to best tune snort given
only one side of a link?
I understand that it is best to get both sides together, but that is not
a possibility in this case. From talking to other network admins, I
understand that this is also not as uncommon as it would seem,
especially dealing with high speed links.
More information about the Snort-users