LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-13-2004, 02:33 PM   #1
kemplej
Member
 
Registered: Dec 2003
Posts: 235

Rep: Reputation: 30
Transparent IDS


What would I put in my rc.firewall to make a transparent IDS box?
 
Old 09-14-2004, 11:15 AM   #2
littleking
Member
 
Registered: Jun 2003
Location: New Albany, OH
Posts: 190

Rep: Reputation: 30
you would have to use snort or something along that line
 
Old 09-14-2004, 03:13 PM   #3
jymbo
Member
 
Registered: Jan 2003
Posts: 217

Rep: Reputation: 30
I'm assuming you mean transparent NIDS, and not IDS.

You need to first install snort. Then you need to determine what you want to monitor: your internal LAN, or traffic on the external side of your firewall. Since you say you want a transparent NIDS, I'm going to assume you want to place the snort box on the outside of your firewall.

If this is the case, you need to get yourself a true repeating hub (NOT a switched hub), or a switch with a spanner port. The whole idea is repeat the trafffic at your cable/dsl router's ext interface across the sniffing interface of your snort box. Once you got that set up properly, bring up the network interface of the snort box without an IP (so it's transparent) and then start-up snort.

This is just an overview, obviously. YOu can find more detailed info over at the snort site.
 
Old 09-15-2004, 11:44 AM   #4
kemplej
Member
 
Registered: Dec 2003
Posts: 235

Original Poster
Rep: Reputation: 30
I want to monitor whats getting past our current hardware firewall. I have set up snort in the past and it works decent. However we have to set up NAT and dhcpd. Since our router would sit outside of the snort box's firewall. And I have to change the gateway to the snort box to let lan traffic thru. To me thats a stupid step. I want to be able to put the box between the router and our local lan and pass ALL traffic thru without needing to add dhcpd or worry about opening ports on the box.


Justyn
 
Old 09-15-2004, 12:10 PM   #5
jymbo
Member
 
Registered: Jan 2003
Posts: 217

Rep: Reputation: 30
If you want to place a snort sensor behind your router, you simply need to put a repeater inline with the local interface of the router and connect your snort box to the repeater. Another option is if your LAN switch has a spanner port, you can simply connect your snort box there. Since you're sensor is behind your router/firewall, then you don't really need to run it in transparent mode.
 
Old 09-15-2004, 01:42 PM   #6
kemplej
Member
 
Registered: Dec 2003
Posts: 235

Original Poster
Rep: Reputation: 30
repeater inline? Would that be hardware or software?


thanks

Justyn
 
Old 09-15-2004, 01:47 PM   #7
jymbo
Member
 
Registered: Jan 2003
Posts: 217

Rep: Reputation: 30
Quote:
Originally posted by kemplej
repeater inline? Would that be hardware or software?


thanks

Justyn
Get a repeater hub...or a switch with a spanner port to replicate the data from the local interface of your router, then plug your snort box into the repeater.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
transparent routing (IDS) ilnli Linux - Networking 5 06-28-2005 01:12 PM
Transparent (or semi-transparent) mounts systemparadox Linux - General 8 04-01-2005 07:51 AM
Transparent PNGs show up as transparent in Firefox - opaque in IE? vharishankar General 10 01-11-2005 06:54 AM
Ids Tredo Linux - Security 2 11-26-2004 02:13 PM
Ids? zuessh Linux - Security 9 04-26-2003 05:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:36 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration