Questions Regarding Running Multiple Instances of Snort
安井敦哉 via Snort-users <[email protected]> Tue, 28 Nov 2023 12:38:16 +0900
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <CAACpDQK0LMNAKQqFG=s_rwrgdFfunbTHVUTRmRm=bAy2rgmz5Q@mail.gmail.com> |
Dear Team, Hello, I hope this message finds you well. I am writing to seek guidance on a few aspects of deploying Snort in our network. 1. When it comes to running multiple instances of Snort, is there a functionality for inter-instance coordination, similar to what is seen in a Zeek cluster? My intention is to employ a load balancer to distribute network traffic evenly across multiple Snort instances. I am keen to understand whether Snort supports any mechanisms or features to facilitate this type of traffic management and load distribution. 2. In relation to the above, would running each Snort instance within a Docker container be a recommended approach? I am considering this for ease of deployment and scalability, but would like to know if there are any best practices or considerations I should be aware of, especially in terms of performance and security. I would greatly appreciate any advice or insights you could provide on these matters. Your expertise will be invaluable in helping us optimize our network security setup. Thank you for your time and assistance. Best regards, AY _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette