Can someone give some help on how to run snort.
Download the tarball from snort.org (latest is 2.1.0) and pcre from
www.pcre.org.
Install pcre, then run "rpmbuild -ta (name of tarball)" and install.
Check out the Snort docs before you configure Snort, make sure you only load the rules you need and also pay attention to how you log. Logging in unified binary format is faster, but then you need to install "Barnyard" from snort.org/contrib.
*I just installed a static Snort-2.1.0 binary with pcre-3.4 using a customized spec file, if anyone is interested I'll post the diff.
I am concerned with port scanners on the computer. I have also heard that linux is commonly port scanned a lot.
"Common" portscanning should not be a "problem". Best is to ignore them script kiddies unless the scanning becomes excessive or if it's followed by an attack. Also read up on current scanning and worm behaviour so you don't go beserk with each alert for IIS and Nachia scans.
I also get a lot of hits on the firestarter. I block the port and host. Am I doing good precautions for setting up the firewall or should I do more than just useing the firestarter?
Setting your default policy to DROP would be a good start wrt the firewall.
Wrt a firewall being enough I'd say this is a rather broad topic and that overlaps your other question in this forum. Best not to have ppl duplicate their efforts helping you.