[Snort-users] Snort in a cluster

Michael Stone mstone+snort at ...10946...
Mon Jul 12 14:27:00 EDT 2004


On Mon, Jul 12, 2004 at 09:52:14AM +0100, Alex Butcher, ISC/ISYS wrote:
>>Or you can adjust the pcap filter so snort sees less traffic.
>
>Out of interest, how do you divide up the traffic? TCP vs. UDP? ports 
>0-32767 vs 32768-65535? Or some other way?

Anyway that makes sense for your environment. Some I divide by port,
some by ip range. It's enough on some systems just to do 80 and !80.

>>I've had good success running multiple snorts on one system where each
>>sees part of the traffic and together they can keep up with a faster link 
>>than a single process trying to watch everything.
>
>I won't deny your experience, but that doesn't make much sense! *shrug*

It doesn't make sense that dividing a traffic stream in half and giving
each half its own processor allows more traffic to be monitored than
trying to watch the same traffic with a single processor?

Mike Stone




More information about the Snort-users mailing list