• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 630
  • Last Modified:

Snort and PT bypass adapter

I'm using a Snort IDS for my company, which runs on CentOS. The system is working currently using a single tap, but I need to expand into several more subnets in the immediate future. Instead of installing several Us work of taps, my sales rep suggested that I use bridge or bypass cards. I'm not too familiar with anything beyond standard multi port network cards so I'd like some unbiased input on what to purchase.

So far, I like the look of the Intel PRO/1000 PF bypass cards. The automatic fail over to continue network operations looks great, and the ability to both monitor and shape traffic in the same location is appealing.  I've read about plenty of people using the general PRO/1000 PF family cards, but nothing I've read has anything specifically about these bypass cards.
Can I use these cards without writing up a specialized driver or using proprietary software? If not, what alternatives do I have?
2 Solutions
Sounds like you have snort on inline mode - IPS and using open source snort?  I've used the commerical version of snort - Sourcefire.  What they did is bind physical interfaces into a single virtual interface and setup that virtual interface to be monitored for intrusions.

I haven't tried this on open source snort before - but I will now - it sounds interesting.....  

Another alternatlive you could do is monitor your gateway - if you have a core switch or core router that distributes across multiple vlans.  Just span those ports into your snort box.
Rich RumbleSecurity SamuraiCommented:
If you have Cisco switches, Catalyst at least, you can do remote span sessions: http://www.cisco.com/warp/public/473/41.html#topic4-2 Or there are devices you can but to tie multiple span ports together
If you are using snort inline, this won't work for you.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Easily Design & Build Your Next Website

Squarespace’s all-in-one platform gives you everything you need to express yourself creatively online, whether it is with a domain, website, or online store. Get started with your free trial today, and when ready, take 10% off your first purchase with offer code 'EXPERTS'.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now