Re: Running Snort 3 on multiple VLANs
victor via Snort-users <[email protected]> Thu, 5 Mar 2026 18:36:04 +0100 (CET)
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
--===============0418954814298427241== Content-Type: multipart/alternative; boundary="----=_Part_194688_837158908.1772732164649" ------=_Part_194688_837158908.1772732164649 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable To obtain a wider range of results, you could apply three methods: a) a single Snort instance for all three VLANs together b) separate Snort instances for each VLANs c) a separate Snort instance for the physical interface on the server, for = example: Snort > Eth0 interface < physical=C2=A0 Finally, you can purge the different logs and analyze which of the three me= thods yields the best results. Think too about the algorithms from snort interfaces For example: aho-corasick (oe-ac) -----------------------><----------------------- Victor GuillenNetworking, Unix & Unix-Like=20 Network infrastructure:~$ Mar 5, 2026, 15:25 by [email protected]: > > Hello everyone! > > > =C2=A0 > > > I am new to Snort 3 and we are preparing to build Snort Servers to monito= r a few different VLANs that are on their own network interface.=C2=A0 We w= ill have this same setup at about 3 other sites and that data will be sent = to a Wazuh server.=C2=A0 When configuring snort 3 to passively monitor each= network interface/VLAN, should we run one instance of snort and have it mo= nitor the three different VLANs, or should we have a separate instance for = each VLAN?=C2=A0 > > > =C2=A0 > > > Oren Kirchhoff > > > =C2=A0 > > > - Computer Services - Information Security Specialist > > > - Phone:> =C2=A0660-263-4100 x11348 > > > - Email:> [email protected] > > ------=_Part_194688_837158908.1772732164649 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"content-type" content=3D"text/html; charset=3DUTF-8= "> </head> <body> <div dir=3D"auto">To obtain a wider range of results, you could apply three= methods:<br></div><div dir=3D"auto"><br></div><div dir=3D"auto">a) a singl= e Snort instance for all three VLANs together<br></div><div dir=3D"auto"><b= r></div><div dir=3D"auto">b) separate Snort instances for each VLANs<br></d= iv><div dir=3D"auto"><br></div><div dir=3D"auto">c) a separate Snort instan= ce for the physical interface on the server, for example:<br></div><div dir= =3D"auto"><br></div><div dir=3D"auto">Snort > Eth0 interface < physic= al <br></div><div dir=3D"auto"><br></div><div dir=3D"auto">Finally, yo= u can purge the different logs and analyze which of the three methods yield= s the best results.<br></div><div dir=3D"auto"><br></div><div dir=3D"auto">= Think too about the algorithms from snort interfaces<br></div><div dir=3D"a= uto"><br></div><div dir=3D"auto">For example: aho-corasick (oe-ac)</div><di= v dir=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=3D"auto"><b><= span class=3D"" style=3D"font-size:13px"><i>-----------------------><= -----------------------</i><br></span></b><span class=3D"" style=3D"font-si= ze:13px"><b>Victor Guillen</b></span></div><div xmlns=3D"http://www.w3.org/= 1999/xhtml" dir=3D"auto"><div dir=3D"auto"><i><span>Networking, Unix & = Unix-Like </span><span class=3D"" style=3D"font-size:11px"><br></span><span= class=3D"" style=3D"font-size:12px">Network <span>infrastructure</span></s= pan></i></div><div dir=3D"auto">:~$<br></div></div><div dir=3D"auto"><br></= div><div dir=3D"auto"><br></div><div dir=3D"auto"><br></div><div dir=3D"aut= o"><br></div><div dir=3D"auto"><br></div><div dir=3D"auto">Mar 5, 2026, 15:= 25 by [email protected]:<br></div><blockquote class=3D"tutanota_q= uote" style=3D"border-left: 1px solid #93A3B8; padding-left: 10px; margin-l= eft: 5px;"><div class=3D""><p class=3D"">Hello everyone!<br></p><p class=3D= ""> <br></p><p class=3D"">I am new to Snort 3 and we are preparing to = build Snort Servers to monitor a few different VLANs that are on their own = network interface. We will have this same setup at about 3 other site= s and that data will be sent to a Wazuh server. When configuring snort 3 to passively monitor each network interface/VLAN,= should we run one instance of snort and have it monitor the three differen= t VLANs, or should we have a separate instance for each VLAN? <br></p>= <p class=3D""> <br></p><div><p class=3D""><span style=3D"color: black;= "><span class=3D"" style=3D"font-family:Calibri, sans-serif"><span class=3D= "" style=3D"font-size:11pt">Oren Kirchhoff</span></span></span><span style= =3D"color: black;"><span class=3D"" style=3D"font-family:Calibri, sans-seri= f"><span class=3D"" style=3D"font-size:11pt"></span></span></span><br></p><= /div><div><p class=3D""><span style=3D"color: black;"><span class=3D"" styl= e=3D"font-family:Calibri, sans-serif"><span class=3D"" style=3D"font-size:1= 1pt"> </span></span></span><br></p></div><div><p class=3D""><b><span s= tyle=3D"color: black;"><span class=3D"" style=3D"font-family:Calibri, sans-= serif"><span class=3D"" style=3D"font-size:11pt">- Computer Services - Info= rmation Security Specialist</span></span></span></b><span style=3D"color: b= lack;"><span class=3D"" style=3D"font-family:Calibri, sans-serif"><span cla= ss=3D"" style=3D"font-size:11pt"></span></span></span><br></p></div><div><p= class=3D""><b><span style=3D"color: black;"><span class=3D"" style=3D"font= -family:Calibri, sans-serif"><span class=3D"" style=3D"font-size:11pt">- Ph= one:</span></span></span></b><span style=3D"color: black;"><span class=3D""= style=3D"font-family:Calibri, sans-serif"><span class=3D"" style=3D"font-s= ize:11pt"> 660-263-4100 x11348</span></span></span><span style=3D"colo= r: black;"><span class=3D"" style=3D"font-family:Calibri, sans-serif"><span= class=3D"" style=3D"font-size:11pt"></span></span></span><br></p></div><p = class=3D""><b><span style=3D"color: black;"><span class=3D"" style=3D"font-= family:Calibri, sans-serif"><span class=3D"" style=3D"font-size:11pt">- Ema= il:</span></span></span></b><span style=3D"color: black;"><span class=3D"" = style=3D"font-family:Calibri, sans-serif"><span class=3D"" style=3D"font-si= ze:11pt"> [email protected]</span></span></span><br></p></div></blockquot= e><div dir=3D"auto"><br></div> </body> </html> ------=_Part_194688_837158908.1772732164649-- --===============0418954814298427241== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============0418954814298427241==--