Hi, we are running our sensor in promiscous mode so that it doesn't block any traffic and having the cisco even viewer email us the IDS event logs. A log summart we have is like this:
High ...
I have 1 server and I want to stop attack on it (like DOS)
I already install Snort as IDS, but how to make it become IPS (Snort + Iptables?)
Thanks in advanced!
To get up and running quickly I installed a VMDK of Linux, Snort and Base. This is working well and quickly. But now I would like to upgrade Snort and Base to their latest versions and have t...
Please let us know the installation of snort recent version. And I am installing in Redhat Linux.
And also i need Snort tuning. I need to reinstall Snort.
Can someone quickly explain what inline vs passive is in Snort.
I want to implement snort on a virtual server, is snort available as a virtual appliance? If so, where can I get it?
Snort 2.8.5 is not alerting or sending to syslog while running local on a Windows 7 RTM host. If i run it with -v option, I can see where it is capturing traffic but there are no alerts. Has...
Dear,
We have more then 300 client PC in our network. All PC has install Symantec Endpoint Protection with Centralized control of Symantec Endpoint Protection Manager.
We notice there ar...
I have WInXP.
I have tried install on several computers. With different serialcodes. And different copies of Flash CS4 normal and profesisonal and trial versions.
On one computer it have b...
Hi, I am in the process of setting up a few servers. The hardware firewall as already setup with policies (Juniper SSG5) and I am also using the host based firewalls as well. I have not been o...
I would like to have the sensor log remotely to a Kiwi syslog server on the same subnet. I have tried setting the log alerts to point to my host which is resolvable by DNS but no logs are app...
Hi Experts,
I am making my first attempt at setting up a Snort IDS system.
Is it best practice for snort to be running inline (over two bridged nics on a linux server) or from a span po...
I am seeking opinions on hardware recommendations to implement a snort IDS to monitor a gigabit network.
i tried implementing in the past with old hardware that was not adaquate.
i'm wor...
I install ok Snort + IDSCenter + Winpcap
OS: w2003
Snort run well, but I have not rule for DOS HTTP
my server run IIS
I 'attack' DOS by sending 1000 query/s to home page, but Snort not r...
Recently, I tried to install Exchange 2007 on a Server 2008 R2 box. The Client Access and Hub Transport Roles installed just fine. However the Mailbox role installation failed. After some r...
Hi,
I received following alert from an IDS that's connected within our internal LAN
& it's reporting that our Internet-facing firewall (HA cluster virtual IP address is
203.120.96.205 ) i...
I tried setting up snort etc on linux and got no where so i tried this one i was told that was easy to use called easy ids. i have installed it on a p4 2gig machine with one network card. i co...