Snort and PT bypass adapter
Posted on 2008-06-20
I'm using a Snort IDS for my company, which runs on CentOS. The system is working currently using a single tap, but I need to expand into several more subnets in the immediate future. Instead of installing several Us work of taps, my sales rep suggested that I use bridge or bypass cards. I'm not too familiar with anything beyond standard multi port network cards so I'd like some unbiased input on what to purchase.
So far, I like the look of the Intel PRO/1000 PF bypass cards. The automatic fail over to continue network operations looks great, and the ability to both monitor and shape traffic in the same location is appealing. I've read about plenty of people using the general PRO/1000 PF family cards, but nothing I've read has anything specifically about these bypass cards.
Can I use these cards without writing up a specialized driver or using proprietary software? If not, what alternatives do I have?