LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 11-24-2009, 09:34 PM   #1
sir-lancealot
Member
 
Registered: Aug 2007
Posts: 346

Rep: Reputation: 31
IDP/IDS question / suggestion


We recently had a FW hardware failure and I replaced it with a basic ubunutu server running iptables and it seems to be working well. One of our sites came under a denial of service attack and I am looking at an IDP type solution and wondering about snort. Can I run this app (or another that people can suggest) on the firewall and/or is it recommended?

The box is sitting pretty idle, so not sure on what resources but I am going to start reading up, but thought someone might already have done this and thumbs up it, or says not to, or suggests otherwise.

Thanks
 
Old 11-25-2009, 12:41 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Within a firewall server to defend yourself directly you would probably want snort-inline, which turns snort from an ids to an ips. I've not had too much experience with it over recent years, but certainly you can run it on your generic hardware firewall. What is worth saying though is that a significant percentage of attacks can be filtered out with iptables alone by looking at connection limiting, tarpit destinations and similar, meaning the traffic doesn't even need to hit an ips system. iptables really has from pretty sexy modules, which would quite possibly have mitigated a DDOS with some ease.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Intrusion Detection (IDP) software replacement sir-lancealot Linux - Security 14 02-21-2009 09:25 AM
not a suggestion but rather a question.... tommytomthms5 LQ Suggestions & Feedback 2 07-16-2008 10:08 AM
Newbie IDS Question mpapet Linux - Security 1 05-05-2005 12:19 PM
Question on Prelude IDS pavkb Linux - Security 1 03-12-2003 04:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 04:47 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration