Advertisement

07.23.2008 at 05:19PM PDT, ID: 23590646 | Points: 250
[x]
Attachment Details

Snort IDS on Cisco ASA5505 Switchport Monitor

Asked by Roetzel_Andress in Intrusion Detection Systems (IDS), Networking Protocols, Cisco PIX Firewall

Tags: Snort, Snort, 2.8.2.1, Installed on CentOS 5.2, Cisco, ASA, 5505, asa803-k8.bin

I spent the weekend getting Snort IDS setup in my lab at home. I have an ASA5505 running "asa803-k8.bin". Interface eth0/0 goes to my cable router, interface eth0/1 goes to the sniffing NIC on my Snort box that is configured without an IP address. Interface eth0/2 goes to the managment NIC on my Snort box. When I run TCPDUMP on the Snort box I get no traffic, is there a problem with my ASA config?
Here is a printout of my interface config.. Is there a problem running tcpdump on an interface without an IP address?

interface Vlan1
nameif inside
security-level 100
ip address 192.168.15.1 255.255.255.0
!
interface Vlan2
nameif outside
security-level 0
ip address dhcp setroute
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
description Sniffing Nic of SNORT box
switchport access vlan 2
switchport monitor Ethernet0/0
!
interface Ethernet0/2
description Managment Nic of SNORT box
!
 
 
Reply To This Message
Start Free Trial
[+][-]07.24.2008 at 02:47AM PDT, ID: 22077371

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.24.2008 at 05:46AM PDT, ID: 22078445

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]08.05.2008 at 06:02AM PDT, ID: 22160436

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628