LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-14-2014, 06:19 PM   #1
hermy7
LQ Newbie
 
Registered: Dec 2011
Location: Syd
Distribution: Centos, Red hat
Posts: 25

Rep: Reputation: Disabled
What are the option for IDS and IPS


Hi guys, I currently using Pfsense snort for IDS and IPS.
But I think the UI not really great and not easy to costume the rule.
I have google come up with a lots of options, I need input from who have been used IDS and IPS system.
Prefer open source, great user interface and easy custom rule
Really appreciate for all the input.
 
Old 01-15-2014, 12:20 AM   #2
jag2000
Member
 
Registered: Sep 2003
Location: Ohio
Distribution: Ubuntu 12.04
Posts: 315
Blog Entries: 2

Rep: Reputation: 31
personally I use Astaro UTM. its free for home use if you have a spare pc lying around. i used to run PF and switched to it.
 
1 members found this post helpful.
Old 01-16-2014, 01:06 AM   #3
hermy7
LQ Newbie
 
Registered: Dec 2011
Location: Syd
Distribution: Centos, Red hat
Posts: 25

Original Poster
Rep: Reputation: Disabled
jag2000, thanks for the input. I will have a try in office lab.
Actually will used for office but really prefer open source because of budget.
If anyone have any other input really appreciate it.
 
Old 01-18-2014, 02:38 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
*I'd like to point out that you're responsible for gauging responses (as the first didn't actually address your concerns and didn't give any reason for switching).

Quote:
Originally Posted by hermy7 View Post
If anyone have any other input really appreciate it.
Maybe you could clarify what
Quote:
Originally Posted by hermy7
great user interface
and what
Quote:
Originally Posted by hermy7
easy custom rule
mean to you. As for the latter most IDSes will initially see their rule set tuned to site specs (like why bother with IIS or Solaris sigs if you don't run them) and run automated rule management to reflect that (lots of command line tools available for which you don't need a user interface), so unless you're into crafting your own signatures or have specs changing dynamically why would you need easy rule customization in the first place...
 
Old 02-24-2014, 12:49 AM   #5
hermy7
LQ Newbie
 
Registered: Dec 2011
Location: Syd
Distribution: Centos, Red hat
Posts: 25

Original Poster
Rep: Reputation: Disabled
Maybe you could clarify what
great user interface


System that have build in snort and build in analysts full packet web based snorby example smoothsec or security onion.
Considering of other people easy to used.

easy custom rule
any program that can help to create local rule just type requirement will automatically create snort rules.
Example filter for RED 5 traffic with specific parameter need to be excluded for security purpose.

Thanks.
 
  


Reply

Tags
ids, ips



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Howto Setup a Basic IDS/IPS on a Linux Server LXer Syndicated Linux News 0 05-29-2012 04:20 PM
What are Linux Based IPS/ IDS devices and their functions ? Nilesh Linux - Security 0 11-23-2011 10:02 AM
[SOLVED] Linux Wireless IDS/IPS ?? tekhead2 Linux - Security 4 09-21-2011 10:01 AM
Virtualization - OS, Firewall, RAS/NAS, IDS/IPS on one system? akakwangkyu Linux - Security 4 03-27-2011 01:57 AM
IDS and IPS in Linux sharma_arpit Linux - Networking 2 10-11-2005 12:07 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:47 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration