Re: Snort 3.0 Deployment
Ron Jenkins <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <SN6PR13MB2432090FB40E028799C39C52E19C9@SN6PR13MB2432.namprd13.prod.outlook.com> |
Good afternoon; I have been deploying Snort for nearly 20 years. Feel free to reach out to me directly. Thanks! Ron Jenkins (Owner / Senior Architect) RMJ Consulting, LLC. " Supporting Companies with their Technology needs" 11715 Bricksome Ave STE B-7 Baton Rouge, LA 70816 Direct. 225-448-5214 Ext #101 Cell. 225-931-1632 Web. http://www.rmjconsulting.net<http://www.rmjconsulting.net/> Log Siphon. http://www.logsiphon.com<http://www.logsiphon.com/> Linkedin. www.linkedin.com/in/ronmjenkins/<http://www.linkedin.com/in/ronmjenkins/> Twitter: www.twitter.com/RMJConsulting<http://www.twitter.com/RMJConsulting> Facebook: www.facebook.com/rmjcsconsulting<http://www.facebook.com/rmjcsconsulting> From: Snort-users <[email protected]> On Behalf Of Aaron Goodman Sent: Wednesday, August 3, 2022 3:51 PM To: [email protected] Subject: [Snort-users] Snort 3.0 Deployment CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders. Hello Everyone, The company i work for right now has a tight budget and they have asked me to deploy a IDS system on our network. We already have meraki firewalls which use the snort rules since snort was acquired by cisco therefore i was thinking about keeping everything consistent by deploying snort on the rest of the network. A one year license is only 399, seems like snort is the way to go? im used to setting up port mirroring on the core switches and attaching the IDS to the mirrored port. It can then pick up all of the network traffic and report back if it detects an intrusion. Is snort setup the same way? Do I need a seperate box for snort or can I deploy on a virtual machine? In vmware, promiscous mode is allowed therefore a vm deployment shouldnt be an issue but we are using hyper-v in this shop and i dont know if the NIC can be setup the same as in vmware. Any other useful info will be greatly appreciated. Especially training material etc. Aaron Thank you, Aaron Goodman - IT Engineer [CHI Logo] 201-B Middlesex Center BLVD Monroe Township, NJ 08831 Phone - 732-393-1800<tel:212.213.1096;211> ext. 347 Fax - 732-641-2567 Email - [email protected]<mailto:[email protected]> Don't forget to visit the YMF Help Desk portal for all your IT needs. https://ymf.sysaidit.com/servicePortal P Please consider the environment before printing this e-mail This e-mail may contain confidential or privileged information. If you think you have received this e-mail in error, please advise the sender by reply e-mail and then delete this e-mail immediately PRIVILEGED & CONFIDENTIAL COMMUNICATION: The information contained in this transmission may be privileged, confidential, and exempt from disclosure under applicable law. It is intended only for the use of the intended recipient. If you are not the intended recipient, you are hereby on notice that any unauthorized disclosure, dissemination, distribution, duplication, or taking any action in reliance on the contents of the electronically transmitted materials or contents of this communication is strictly prohibited. If you have received this communication in error, please contact the sender by reply e-mail and destroy all copies of the original message. _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette
image001.jpg
(image/jpeg, 3.7 KB) - not displayed