LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-25-2006, 02:22 PM   #1
Palula
Member
 
Registered: May 2005
Location: Brazil
Distribution: Fedore Core 3
Posts: 138

Rep: Reputation: 15
Question Snort: Putting the IDS inside/outside network...


Hello fellas...

Info of my network structure

- Linux Server --- Snort runs on this machine --- :

Which is the router of the network within my apartment. It is natting the internet connection to the clients, serving Dhcp, has an iptables configured firewall (has two ethīs of course. The home network NIC (eth1) and the outside (internet) NIC (eth0)).

- Client 1 (Windows 98)

- Client 2 (Windows XP)

Ok! Here is the concern: What would be the correct way to make snort analyze portscans, dos attacks, overflow attacks to my Linux server coming from the outside network?

My snort HOME_NET variable stands for an IP inside my network (i.e: 192.168.0.0/24). Is this right? Isnīt snort, then, analyzing attacks, portscans and exploits that happen from my very own network towards my very own network? For example DOS attacks from machine 192.168.0.45 towards machine 192.168.0.197 (assuming these are valid IPīs within the network)?

Sorry about the loooooooooong question.
Thank you very much!
 
Old 01-25-2006, 05:36 PM   #2
mpapet
Member
 
Registered: Nov 2003
Location: Los Angeles
Distribution: debian
Posts: 548

Rep: Reputation: 72
1. By NATing are you including firewall functions on the same box with snort? I am hoping you aren't because it's not wise.

2. If you put a tap outside the firewall, it will be much busier analyzing traffic so be sure you have the resources to capture a meaningful amount of packets.

3. To listen outside the firewall, you need a simple switch outside the firewall and a second ethernet port inside the snort box. CAREFULLY follow ethernet tap making instructions to listen only and connect the tap to the second ethernet adapter and the switch.

Watching inside-only traffic is not a bad thing.
 
Old 01-27-2006, 11:21 AM   #3
Palula
Member
 
Registered: May 2005
Location: Brazil
Distribution: Fedore Core 3
Posts: 138

Original Poster
Rep: Reputation: 15
Nice but...

Letīs suppose Iīm using a switch -- and the IDS machine will be a totally diffrent machine (I understood why itīs not good for the router/firewall machine to be the IDS machine too) --. Switches will map the ports. So a packet with destination to IP xxx.xxx.xxx.xxx will only be sent to the port where xxx.xxx.xxx.xxx is connected to. Right? So the IDS machine (even setting eth0 or 1 or 2 etc to promiscuous mode) will only receive connections destined to itīs IP.

Another concern is that the IDS has two cards. One to be connected with the internal network and another to the hub, which will be splitting the raw connection coming from the internet... Before the router/firewall right? So Ok. Letīs say interface 1 has an IP inside the network. But what about the second card. Which IP will it have? It has to have an IP doesnīt it?

Letīs talk ADSL. I have an IP assigned to my router/firewall via DHCP but when I plug the router and IDS cables to the hub the ISP will have to assign two IPīs via DHCP wonīt it?

And what about security. What kind of security does the IDS (tottaly separate) machine has. How do we secure it?

Thanks you very much! :-)
 
Old 01-27-2006, 11:30 AM   #4
mpapet
Member
 
Registered: Nov 2003
Location: Los Angeles
Distribution: debian
Posts: 548

Rep: Reputation: 72
Rtfm

If you don't want to take the time to learn from the immense amount of information widely available on setting up snort then I'm not sure why you even started the thread.

Of course, if you'd like to pay me to do the setup for you, then contact me directly.
 
Old 01-27-2006, 01:54 PM   #5
Palula
Member
 
Registered: May 2005
Location: Brazil
Distribution: Fedore Core 3
Posts: 138

Original Poster
Rep: Reputation: 15
Sorry to bother and thanks anyway. :-)
 
Old 01-27-2006, 03:34 PM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by mpapet
if you'd like to pay me to do the setup for you, then contact me directly.
//Moderator note: LQ is a community provided to free of charge. Please do not try take advantage of that fishing for jobs. It is respectless towards LQ's owner and your fellow LQ members alike.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
developing an ids using snort chax Linux - Security 1 01-10-2006 12:20 PM
developing an ids using snort chax Linux - Networking 1 01-10-2006 11:51 AM
Questions regarding the use of Snort (IDS) and security nasty_daemon Linux - Security 8 09-09-2005 10:48 PM
Snort/ACID as an IDS WeNdeL Linux - Security 4 09-10-2004 12:14 PM
snort (ids) not working please help!!! crealkillerI75 Slackware 5 07-18-2002 03:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:00 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration