Re: Snort 3.0 Deployment
Joel Esler via Snort-users <[email protected]>
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
> On Aug 3, 2022, at 4:50 PM, Aaron Goodman <[email protected]> wrote: > > The company i work for right now has a tight budget and they have asked me to deploy a IDS system on our network. We already have meraki firewalls which use the snort rules since snort was acquired by cisco therefore i was thinking about keeping everything consistent by deploying snort on the rest of the network. A one year license is only 399, seems like snort is the way to go? > > im used to setting up port mirroring on the core switches and attaching the IDS to the mirrored port. It can then pick up all of the network traffic and report back if it detects an intrusion. Is snort setup the same way? Exactly. Unless you want it in inline mode to block things, but otherwise yes. > > Do I need a seperate box for snort or can I deploy on a virtual machine? In vmware, promiscous mode is allowed therefore a vm deployment shouldnt be an issue but we are using hyper-v in this shop and i dont know if the NIC can be setup the same as in vmware. I would suggest dedicated hardware, but it’s up to you. > > Any other useful info will be greatly appreciated. Especially training material etc. I would suggest starting here: https://snort.org/resources — Joel _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette