Re: [sentinix-list] SnortCenter Agent, remote deployment
Michel Blomgren <[email protected]>
| Newsgroups | gmane.linux.sentinix |
|---|---|
| Message-ID | <[email protected]> |
On Monday 29 December 2003 19:32, M. Morgan wrote:
> Hello all,
> In regards to the sentinix setup utility, I have a question in regards to
> choosing "network services" to determin which services will be loaded at
> boot time.
>
> I'd like to deploy remote (off server) Snort nodes, this requires the
> installation of "Snortcenter Agent", Snort, OpenSSL, Perl and some other
> packages on the remote node. The intent is to have several remote nodes
> report to a central MySQL database (on sentinix) and administer them all
> from there.
That's the strategic, good approach. Since you can't choose what to install
and not install (yet), everything gets installed without you being able to
neither install specific packages or remove any packages (there's no package
system even). You can install several Sentinix's all around yer net(s), and
choose only to run Snort+SnortCenter+SnortCenter Sensor Agent on the "nodes".
You can re-configure the "output plugin" from SnortCenter to use a central
(another than localhost) MySQL server (basically anyone, doesn't have to be a
sentinix box). That MySQL server will have to have a Snort database
structure though.
>
> The Setup utility has the options to install "Snort" only with no mention
> of the SnortCenter in both its parts (niether the admin console or the
> remote agent).
>
> Heres the question:
> So, in order to load sentinix as a remote sensor agent, NTP and SSH are
> the only services you could load from the cd...the rest would need to be
> installed via source packages?
Basically, for a "snort node": SnortCenter Sensor Agent (loads Snort for you
and lets you configure Snort remotely through SnortCenter), SSH (if you
choose to), NTP (is always good!).
For the central server: MySQL + Apache (should be it). You'll add and
configure each node's SnortCenter Sensor Agent in the central server's
SnortCenter (web interface). It's just as a local uni-installation, except
it's separated on different boxes.
If you mean sentinix; no need to install anything, you just have to
re-configure it not to use localhost MySQL on the "snort nodes" ("output
plugin" in SnortCenter).
>
> If this is the case it may be prudent to include the menu options to
> install sentinix as a remote snort node in the next release.
The next release will include binary packaging, so you may specifically select
what to actually install on any system. As for setting up a remote snort
node, you'll still have to configure it to fit your system (your IPs, rules,
mysql server, etc.) from SnortCenter.
Michel
>
>
> required package information for snortcenter console/agent is here:
> http://users.pandora.be/larc/download/
>
> Thanks,
> Michael
>
>
> _______________________________________________
> SENTINIX mailing list
> [email protected]
> http://elevenprospect.com/mailman/listinfo/sentinix