Tobywuk
August 17th, 2009, 04:15 PM
I am thinking about installing an Intrusion detection system on my network using a dedicated box running linux and snort.
Is it possible to place the box between my cable modem and Router, using two NIC's to relay the traffic back and forward?
If I were to do this, How would I get the traffic to be sent to/from each network card so the traffic "passes through" the box?
How would I then get snort to pick up the network traffic? From what I have read it works just by setting a NIC into promiscuous mode, but if i did this then I couldn't relay traffic?
Perhaps this is not the best way to do it and it would be better to just install a Hub (broadcasting data to all ports) and then attaching the snort box to this in promiscuous mode?
Is it possible to place the box between my cable modem and Router, using two NIC's to relay the traffic back and forward?
If I were to do this, How would I get the traffic to be sent to/from each network card so the traffic "passes through" the box?
How would I then get snort to pick up the network traffic? From what I have read it works just by setting a NIC into promiscuous mode, but if i did this then I couldn't relay traffic?
Perhaps this is not the best way to do it and it would be better to just install a Hub (broadcasting data to all ports) and then attaching the snort box to this in promiscuous mode?