Re: snort for ipcop 2.x
David Taylor <daveytay-wUU9E3n5/[email protected]>
| Newsgroups | gmane.comp.security.ipcop.devel |
|---|---|
| Message-ID | <[email protected]> |
On 10/05/2012 4:56 p.m., David W Studeman wrote: > The creation of the addon was inevitable as there are people who don't > think they can live without Snort, not the least of which is the author > of the addon. Hopefully, he'll get it polished up and include more > languages so it is usable by Snort devotees that insist on having Snort. > As far as the reasons why the developers did not include it is well > covered in this list a few years back but yeah, it would be a pain to > maintain it. Other reasons are in line with my own reasons not to use > it. False positives, high memory usage and so on. Basically extra noise > that clouds the ability to see in a nutshell what's really happening at > the firewall. > > I'm curious to see how well the folks do if they enable the inline > (active) option with the full ruleset as downloaded directly from Snort. > Anyone care to bet on how many pissed off internet users result from > this option? > > I know that I used to have to look at logs and find the rule and turn it off, and that was just for my 2 PC home LAN, because my remote admin to a green PC rule would stop working on IPCop V 1.4 :(. I also know of some sysadmins who like to make work for themselves... This is a very easy way to make yourself very busy for little benefit. I think setting up a labrea tarpit would be more effective if you were after blocking stuff. -- Ciao, Dave ------------------------------------------------------------------------------ Live Security Virtual Conference Exclusive live event will cover all the ways today's security and threat landscape has changed and how IT managers can respond. Discussions will include endpoint security, mobile security and the latest in malware threats. http://www.accelacomm.com/jaw/sfrnl04242012/114/50122263/