[Snort-users] Snort in a cluster
mstone+snort at ...10946...
Mon Jul 12 14:27:00 EDT 2004
On Mon, Jul 12, 2004 at 09:52:14AM +0100, Alex Butcher, ISC/ISYS wrote:
>>Or you can adjust the pcap filter so snort sees less traffic.
>Out of interest, how do you divide up the traffic? TCP vs. UDP? ports
>0-32767 vs 32768-65535? Or some other way?
Anyway that makes sense for your environment. Some I divide by port,
some by ip range. It's enough on some systems just to do 80 and !80.
>>I've had good success running multiple snorts on one system where each
>>sees part of the traffic and together they can keep up with a faster link
>>than a single process trying to watch everything.
>I won't deny your experience, but that doesn't make much sense! *shrug*
It doesn't make sense that dividing a traffic stream in half and giving
each half its own processor allows more traffic to be monitored than
trying to watch the same traffic with a single processor?
More information about the Snort-users