Re: snort / prelude-manager certificate trust
ScottO <[email protected]> Fri, 20 Nov 2009 15:19:30 -0500
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <[email protected]> |
> > Right, I understand the different profiles for different components, but I > guess I was failing to see the relationship between all of the components. I > was expecting to register a "snort" profile on my snort sensor with a > corresponding "snort" profile on the prelude-manager machine. I also had to > register prelude-manager with itself (after adding the profile) to get > things working properly. In the architecture diagram on the Prelude wiki, it > appears to show several layers in a hierarchy of reporting from remote > sensors to remote prelude-managers, which then in turn report back in to a > centralized prelude-manager somewhere else. I'd like to explore that setup > at some point (since I will eventually have some remote sensors) so I expect > I'll have some further questions in the future. I'm guessing that in that > case, I'd want to register the remote snort profile against the remote > prelude-manager profile, and then register the remote prelude-manager > profile with the central prelude-manager profile? > > yep, that's exactly right. register each agent/manager with their direct upstream manager. scotto _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-user