[Snort-users] Advice on Snort Inline

Mark Rohrbeck mark.rohrbeck at ...11827...
Fri Sep 8 08:12:50 EDT 2006


Hi all, 

I have 2 IDS systems in place and tuned to their specific networks, the next
step I want to take is running them with Snort_inline. I am just a little
unsure on how to do this. I would prefer to use Fedora Core 5 as the OS but
open to suggestions. I mainly want to find out if I can run Snort_inline on
one box? 

The networks are pretty small with 10 - 50 XP PC's and server 2003 / 2000,
we run Sonicwall firewalls and I have the Sensors behind the firewall. The
picture I have in my mind is having 3 nics in the machine, 1 for Admin and
the other 2 for Snort inline. Am I heading in the right direction here?

Any advice / help GREATLY appreciated.

Marklar





More information about the Snort-users mailing list