Snort 3.0 Deployment

Aaron Goodman <[email protected]>
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <BL3P221MB0596EAEBBE96453708A9DBADA39C9@BL3P221MB0596.NAMP221.PROD.OUTLOOK.COM>
Hello Everyone,

The company i work for right now has a tight budget and they have asked me to deploy a IDS system on our network.  We already have meraki firewalls which use the snort rules since snort was acquired by cisco therefore i was thinking about keeping everything consistent by deploying snort on the rest of the network.  A one year license is only 399, seems like snort is the way to go?

im used to setting up port mirroring on the core switches and attaching the IDS to the mirrored port.  It can then pick up all of the network traffic and report back if it detects an intrusion.  Is snort setup the same way?

Do I need a seperate box for snort or can I deploy on a virtual machine?  In vmware, promiscous mode is allowed therefore a vm deployment shouldnt be an issue but we are using hyper-v in this shop and i dont know if the NIC can be setup the same as in vmware.

Any other useful info will be greatly appreciated.  Especially training material etc.

Aaron


Thank you,

Aaron Goodman - IT Engineer

[CHI Logo]
201-B Middlesex Center BLVD
Monroe Township, NJ 08831
Phone - 732-393-1800<tel:212.213.1096;211> ext. 347
Fax - 732-641-2567
Email - [email protected]<mailto:[email protected]>

Don't forget to visit the YMF Help Desk portal for all your IT needs.
https://ymf.sysaidit.com/servicePortal


P  Please consider the environment before printing this e-mail
This e-mail may contain confidential or privileged information. If you think you have received this e-mail in error, please advise the sender by reply e-mail and then delete this e-mail immediately

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
image001.jpg (image/jpeg, 3.7 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.