LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 12-22-2003, 10:15 AM   #1
MastaYoda
LQ Newbie
 
Registered: Dec 2003
Distribution: Mandrake 9.2, open to all others though
Posts: 19

Rep: Reputation: 0
Question The Best Distro to run Snort?


just curious which is preferred...that is if there is a preferred?

Last edited by MastaYoda; 12-22-2003 at 10:19 AM.
 
Old 12-22-2003, 10:20 AM   #2
jcookeman
Member
 
Registered: Jul 2003
Location: London, UK
Distribution: FreeBSD, OpenSuse, Ubuntu, RHEL
Posts: 417

Rep: Reputation: 33
there are none
 
Old 12-22-2003, 10:23 AM   #3
MastaYoda
LQ Newbie
 
Registered: Dec 2003
Distribution: Mandrake 9.2, open to all others though
Posts: 19

Original Poster
Rep: Reputation: 0
Do you mean there isn't a difference or that you just don't like running snort? I am also looking for ease of setup (not of the os...just for installing snort). Thanks for responses!
 
Old 12-22-2003, 11:43 AM   #4
MastaYoda
LQ Newbie
 
Registered: Dec 2003
Distribution: Mandrake 9.2, open to all others though
Posts: 19

Original Poster
Rep: Reputation: 0
Anyone with any thoughts on this? Anything would be helpful.
 
Old 12-22-2003, 11:44 AM   #5
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
Looking at the Snort pages, they seem to recommend Redhat, Solaris, FreeBSD and Windows 2000 - at least that is what they seem to install on. If Snort is to be run on it's own, you need a smallish distro with very little running, which you can then strip down.

What do you want to run it on?
 
Old 12-22-2003, 11:49 AM   #6
MastaYoda
LQ Newbie
 
Registered: Dec 2003
Distribution: Mandrake 9.2, open to all others though
Posts: 19

Original Poster
Rep: Reputation: 0
Thanks for the help XP...I was looking at RedHat, but a friend of mine who is more skilled in linux likes mandrake and slackware. I looked at snort.org and couldn't find anything on mandrake or slackware, just redhat. Just curious what other people, with much more expierence than myself thought. RedHat was my first choice though, mostly because i could find more info on snort.org about it.
 
Old 12-22-2003, 11:54 AM   #7
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
Go with redhat - if you don't like it, change it. I've never run it, so have no first hand advice to offer.
 
Old 12-22-2003, 11:57 AM   #8
MastaYoda
LQ Newbie
 
Registered: Dec 2003
Distribution: Mandrake 9.2, open to all others though
Posts: 19

Original Poster
Rep: Reputation: 0
Well i will give it a shot...we already have a slackware and a redhat machine up so we will experiment and i will try to post back after my experience for future reference.

p.s. i read back through the rules...sorry i missed that one
 
Old 12-22-2003, 12:08 PM   #9
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 475Reputation: 475Reputation: 475Reputation: 475Reputation: 475
You are not the first to do a double post and you certainly won't be the last

You could put your report in the LQ success stories or security forum - it's possible it could even be made a sticky.....
 
Old 12-22-2003, 12:39 PM   #10
ghight
Member
 
Registered: Jan 2003
Location: Indiana
Distribution: Centos, RedHat Enterprise, Slackware
Posts: 524

Rep: Reputation: 30
ClarkConnect runs on Redhat (RedHat based) and already has snort setup and ready to go. They have a good web interface too. Its a small download so try it. You can update it with the RedHat repositories too.
 
Old 12-22-2003, 12:42 PM   #11
jcookeman
Member
 
Registered: Jul 2003
Location: London, UK
Distribution: FreeBSD, OpenSuse, Ubuntu, RHEL
Posts: 417

Rep: Reputation: 33
As far as snort is concerned there is no preference as to what Linux you run on. There are packages available for Debian, Slackware and it's in the Gentoo portage. It's in FreeBSD ports and OpenBSD ports. You can install it on any distribution or BSD that you like.

Once the installation is complete they are vitually the same. If you want to run snort on a gateway box then you better make sure it is tuned well, depending on the amount of traffic. If you have the capability I would run snort on a linux/BSD box connected to a switch that allows port monitoring, that way it would be dedicated.

Here is a link so you get the idea:
http://www.cisco.com/warp/public/473/41.html
 
Old 12-22-2003, 12:48 PM   #12
MastaYoda
LQ Newbie
 
Registered: Dec 2003
Distribution: Mandrake 9.2, open to all others though
Posts: 19

Original Poster
Rep: Reputation: 0
Thanks a ton guys....more research and some expirementing to do now Keep those helpful hints comeing! Thanks again!
 
Old 12-22-2003, 12:48 PM   #13
ghight
Member
 
Registered: Jan 2003
Location: Indiana
Distribution: Centos, RedHat Enterprise, Slackware
Posts: 524

Rep: Reputation: 30
While informative to say the least, that's not really newbie-ized info. A true "trial by fire".
 
Old 12-22-2003, 01:05 PM   #14
MastaYoda
LQ Newbie
 
Registered: Dec 2003
Distribution: Mandrake 9.2, open to all others though
Posts: 19

Original Poster
Rep: Reputation: 0
I've been burned atleast once by almost everything......snort would not be the first! Thanks for the warning though. I have other expertise help as well So i cant get burned but so bad!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Best distro to use for Snort hywaydave23 Linux - Security 6 08-29-2005 11:33 PM
Which Linux Distro better suited for Snort? jolu2000 Linux - Distributions 1 07-07-2004 08:14 PM
What is the best Distro to run Snort on? MastaYoda Linux - General 5 12-22-2003 01:24 PM
What distro is better for running snort? MastaYoda Linux - Networking 2 12-22-2003 01:07 PM
Looking for a sercure Linux distro w/ snort Thaidog Linux - Newbie 2 09-29-2002 02:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 11:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration