[Snort-users] Snort, BASE, and FRW

Shomiron Das Gupta shomiron at ...11827...
Tue Sep 25 15:37:46 EDT 2012


Few questions:
 -- What firewalls are these?
 -- Do they have preinstalled snort running on them?
 -- Are these firewalls running on HA?

These will help us get a correct analysis.

Shomiron Das Gupta

twitter: @shomiron

On Tuesday, 25 September 2012 at 7:30 PM, Joao Daniel Neves wrote:

> Snort Users,
> I'm deploying a snort installation. The enviroment is a bit simple
> two firewalls.  The second firewall is for high-availibilty. 
> Of course, Snort is running in both firewalls.  ;-)
> However, BASE only shows one sensor (with alerts from frw1). Is this acceptable? Is the the correct
> behavior? 
> I think that the answer is 'yes'. Since that firewall2 is sleeping
> and will wake up just if firewall1 is in trouble. 
> ------------------------------------------------------------------------------
> Live Security Virtual Conference
> Exclusive live event will cover all the ways today's security and 
> threat landscape has changed and how IT managers can respond. Discussions 
> will include endpoint security, mobile security and the latest in malware 
> threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/
> _______________________________________________
> Snort-users mailing list
> Snort-users at lists.sourceforge.net (mailto:Snort-users at lists.sourceforge.net)
> Go to this URL to change user options or unsubscribe:
> https://lists.sourceforge.net/lists/listinfo/snort-users
> Snort-users list archive:
> http://www.geocrawler.com/redir-sf.php3?list=snort-users
> Please visit http://blog.snort.org to stay current on all the latest Snort news! 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20120926/cf158203/attachment.html>

More information about the Snort-users mailing list