Re: [sentinix-list] SnortCenter Agent, remote deployment

Michel Blomgren <[email protected]>
Newsgroups gmane.linux.sentinix
Message-ID <[email protected]>
On Monday 29 December 2003 19:32, M. Morgan wrote:
> Hello all,
>  In regards to the sentinix setup utility, I have a question in regards to
> choosing "network services" to determin which services will be loaded at
> boot time.
>
>  I'd like to deploy remote (off server) Snort nodes, this requires the
> installation of "Snortcenter Agent", Snort, OpenSSL, Perl and some other
> packages on the remote node. The intent is to have several remote nodes
> report to a central MySQL database (on sentinix) and administer them all
> from there.

That's the strategic, good approach.  Since you can't choose what to install 
and not install (yet), everything gets installed without you being able to 
neither install specific packages or remove any packages (there's no package 
system even).   You can install several Sentinix's all around yer net(s), and 
choose only to run Snort+SnortCenter+SnortCenter Sensor Agent on the "nodes".  
You can re-configure the "output plugin" from SnortCenter to use a central 
(another than localhost) MySQL server (basically anyone, doesn't have to be a 
sentinix box).  That MySQL server will have to have a Snort database 
structure though.

>
>  The Setup utility has the options to install "Snort" only with no mention
> of the SnortCenter in both its parts (niether the admin console or the
> remote agent).
>
> Heres the question:
>  So, in order to load sentinix as a remote sensor agent, NTP and SSH are
> the only services you could load from the cd...the rest would need to be
> installed via source packages?

Basically, for a "snort node":  SnortCenter Sensor Agent (loads Snort for you 
and lets you configure Snort remotely through SnortCenter), SSH (if you 
choose to), NTP (is always good!).

For the central server:  MySQL + Apache (should be it).  You'll add and 
configure each node's SnortCenter Sensor Agent in the central server's 
SnortCenter (web interface).   It's just as a local uni-installation, except 
it's separated on different boxes.

If you mean sentinix; no need to install anything, you just have to 
re-configure it not to use localhost MySQL on the "snort nodes" ("output 
plugin" in SnortCenter).

>
>  If this is the case it may be prudent to include the menu options to
> install sentinix as a remote snort node in the next release.

The next release will include binary packaging, so you may specifically select 
what to actually install on any system.   As for setting up a remote snort 
node, you'll still have to configure it to fit your system (your IPs, rules, 
mysql server, etc.) from SnortCenter.

	Michel
>
>
> required package information for snortcenter console/agent is here:
> http://users.pandora.be/larc/download/
>
> Thanks,
> Michael
>
>
> _______________________________________________
> SENTINIX mailing list
> [email protected]
> http://elevenprospect.com/mailman/listinfo/sentinix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.